CVE-2013-4409
ReviewBoard and Djblets library are vulnerable to code execution
9.8
CRITICAL
CVSS 3.1
EPSS 3.0%
Description
An eval() vulnerability exists in Python Software Foundation Djblets version before 0.6.30 and 0.7.0 before 0.7.19 and Beanbag Review Board before 1.7.15 when parsing JSON requests allowing an attacker to execute arbitrary Python code.
How to fix CVE-2013-4409
To remediate CVE-2013-4409, upgrade the affected package to a fixed version below.
- PyPI/reviewboard—upgrade to 1.7.15 or later
Is CVE-2013-4409 being exploited?
Low — EPSS is 3.0%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 1.7.15
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 4.0 | — | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
| osv | CVSS 3.1 | CRITICAL9.8 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |