Safety vulnerability ID: 36155
The information on this page was manually curated by our Cybersecurity Intelligence Team.
base/oi/doa.py in the Rope library in CPython (aka Python) allows remote attackers to execute arbitrary code by leveraging an unsafe call to pickle.load.
Latest version: 1.13.0
a python refactoring library...
base/oi/doa.py in the Rope library in CPython (aka Python) allows remote attackers to execute arbitrary code by leveraging an unsafe call to pickle.load.
MLIST:[oss-security] 20150206 python-rope: pickle.load of remotely supplied data with no authentication required: http://www.openwall.com/lists/oss-security/2015/02/07/1
CONFIRM:https://bugzilla.redhat.com/show_bug.cgi?id=1116485: https://bugzilla.redhat.com/show_bug.cgi?id=1116485
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application