CVE-2020-27619
קריטית 9.8
תיאור (מקור, אנגלית)
In Python 3 through 3.9.0, the Lib/test/multibytecodec_support.py CJK codec tests call eval() on content retrieved via HTTP.
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
מוצרים מושפעים
python: python; fedoraproject: fedora; oracle: communications cloud native core network function cloud native environment
קישורים
- https://bugs.python.org/issue41944 Issue TrackingPatchVendor Advisory
- https://github.com/python/cpython/commit/2ef5caa58febc8968e670e39e3d37cf8eef3c… PatchVendor Advisory
- https://github.com/python/cpython/commit/43e523103886af66d6c27cd72431b5d9d14cd… PatchVendor Advisory
- https://github.com/python/cpython/commit/6c6c256df3636ff6f6136820afaefa5a10a3a… PatchVendor Advisory
- https://github.com/python/cpython/commit/b664a1df4ee71d3760ab937653b10997081b1… PatchVendor Advisory
- https://github.com/python/cpython/commit/e912e945f2960029d039d3390ea08835ad393… PatchVendor Advisory
- https://bugs.python.org/issue41944 Issue TrackingPatchVendor Advisory
- https://github.com/python/cpython/commit/2ef5caa58febc8968e670e39e3d37cf8eef3c… PatchVendor Advisory
- https://github.com/python/cpython/commit/43e523103886af66d6c27cd72431b5d9d14cd… PatchVendor Advisory
- https://github.com/python/cpython/commit/6c6c256df3636ff6f6136820afaefa5a10a3a… PatchVendor Advisory