Sqla_yaml_fixtures 0.9.1 allows local users to execute arbitrary python code via the fixture_text argument in sqla_yaml_fixtures.load.
Advisories
Source ID Title
EUVD EUVD EUVD-2019-0132 Sqla_yaml_fixtures 0.9.1 allows local users to execute arbitrary python code via the fixture_text argument in sqla_yaml_fixtures.load.
Github GHSA Github GHSA GHSA-2x54-j4m3-r6wx sqla-yaml-fixtures is vulnerable to Code Injection
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T19:12:09.447Z

Reserved: 2019-01-02T00:00:00

Link: CVE-2019-3575

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-01-03T19:29:01.727

Modified: 2024-11-21T04:42:11.833

Link: CVE-2019-3575

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses