CVE-2011-4212: High severity google app engine python sdk vulnerability
The sandbox environment in the Google App Engine Python SDK before 1.5.4 does not properly prevent os.popen calls, which allows local users to bypass intended access restrictions and execute arbitrary commands via a devappserver.RestrictedPathFunction.originalos reference within the code parameter to ah/admin/interactive/execute, a different vulnerability than CVE-2011-1364.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2011-4212?
CVE-2011-4212 has a medium severity rating as it allows local users to execute arbitrary commands.
How do I fix CVE-2011-4212?
To fix CVE-2011-4212, upgrade the Google App Engine Python SDK to version 1.5.4 or later.
Who is affected by CVE-2011-4212?
Users running Google App Engine Python SDK versions up to 1.5.3 are affected by CVE-2011-4212.
What is the impact of CVE-2011-4212?
The impact of CVE-2011-4212 is that it allows local users to bypass intended access restrictions.
What versions of software are impacted by CVE-2011-4212?
CVE-2011-4212 affects multiple versions of the Google App Engine Python SDK including 1.0.1 through 1.5.3.