CVE-2019-16328
HIGH8.5EPSS 73.0%Duplicate Advisory: Possible remote code execution via a remote procedure call
發布日:2019/11/20修改日:2024/12/6
描述
Withdrawn: duplicate of GHSA-pj4g-4488-wmxm ## Original Description In RPyC 4.1.x through 4.1.1, a remote attacker can dynamically modify object attributes to construct a remote procedure call that executes code for an RPyC service with default configuration settings.
受影響套件(3)
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.5 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N |
參考連結(10)
- ADVISORYhttps://github.com/advisories/GHSA-9ggp-4jpr-7ppj
- ADVISORYhttps://github.com/advisories/GHSA-pj4g-4488-wmxm
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2019-16328
- PATCHhttps://github.com/tomerfiliba-org/rpyc
- WEBhttp://lists.opensuse.org/opensuse-security-announce/2020-05/msg00046.html
- WEBhttp://lists.opensuse.org/opensuse-security-announce/2020-06/msg00004.html
- WEBhttps://github.com/pypa/advisory-database/tree/main/vulns/rpyc/PYSEC-2019-118.yaml
- WEBhttps://github.com/tomerfiliba-org/rpyc/security/advisories/GHSA-pj4g-4488-wmxm
- WEBhttps://github.com/tomerfiliba/rpyc
- WEBhttps://rpyc.readthedocs.io/en/latest/docs/security.html