Description
Uncontrolled deserialization of a pickled object in models.py in Frost Ming rediswrapper (aka Redis Wrapper) before 0.3.0 allows attackers to execute arbitrary scripts.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-0121 | Uncontrolled deserialization of a pickled object in models.py in Frost Ming rediswrapper (aka Redis Wrapper) before 0.3.0 allows attackers to execute arbitrary scripts. |
Github GHSA |
GHSA-vrcf-g539-x6h3 | Uncontrolled deserialization of a pickled object in rediswrapper allows attackers to execute arbitrary scripts |
References
History
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T01:33:17.281Z
Reserved: 2019-10-05T00:00:00.000Z
Link: CVE-2019-17206
No data.
Status : Modified
Published: 2019-10-05T23:15:10.737
Modified: 2024-11-21T04:31:51.563
Link: CVE-2019-17206
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA