CVE-2011-4211: High severity google app engine python sdk vulnerability
The FakeFile implementation in the sandbox environment in the Google App Engine Python SDK before 1.5.4 does not properly control the opening of files, which allows local users to bypass intended access restrictions and create arbitrary files via ALLOWEDMODES and ALLOWEDDIRS changes within the code parameter to ah/admin/interactive/execute, a different vulnerability than CVE-2011-1364.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2011-4211?
CVE-2011-4211 is classified as a medium severity vulnerability.
How do I fix CVE-2011-4211?
To fix CVE-2011-4211, upgrade to Google App Engine Python SDK version 1.5.4 or later.
What are the affected versions for CVE-2011-4211?
CVE-2011-4211 affects versions of Google App Engine Python SDK prior to 1.5.4.
What type of vulnerability is CVE-2011-4211?
CVE-2011-4211 is a file access control vulnerability in the Google App Engine Python SDK.
Who is impacted by CVE-2011-4211?
Local users with access to the Google App Engine Python SDK versions mentioned can exploit CVE-2011-4211.