CVE-2013-4409: Input Validation
An eval() vulnerability exists in Python Software Foundation Djblets 0.7.21 and Beanbag Review Board before 1.7.15 when parsing JSON requests.
Other sources
An eval() vulnerability exists in Python Software Foundation Djblets version before 0.6.30 and 0.7.0 before 0.7.19 and Beanbag Review Board before 1.7.15 when parsing JSON requests allowing an attacker to execute arbitrary Python code.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-4409?
CVE-2013-4409 is classified as a high-severity vulnerability due to its potential to allow arbitrary code execution through improper JSON request parsing.
How do I fix CVE-2013-4409?
To fix CVE-2013-4409, upgrade Djblets to version 0.6.30 or later and ReviewBoard to version 1.7.15 or later.
What software is affected by CVE-2013-4409?
CVE-2013-4409 affects Djblets versions before 0.6.30 and 0.7.19, and ReviewBoard versions before 1.7.15.
What type of vulnerability is CVE-2013-4409?
CVE-2013-4409 is an eval() vulnerability that arises from unsafe parsing of JSON requests in the affected software.
When was CVE-2013-4409 disclosed?
CVE-2013-4409 was disclosed in November 2013.