CVE-2013-5942: Code Injection
Published Sep 27, 2013
·Updated
Graphite 0.9.5 through 0.9.10 uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via a crafted serialized object, related to (1) remotestorage.py, (2) storage.py, (3) render/datalib.py, and (4) whitelist/views.py, a different vulnerability than CVE-2013-5093.
Affected Software
7 affected componentsFixes available
pip/graphite-web>=0.9.5<=0.9.10
0.9.11
Graphite Project Graphite=0.9.5
Graphite Project Graphite=0.9.6
Graphite Project Graphite=0.9.7
Graphite Project Graphite=0.9.8
Graphite Project Graphite=0.9.9
Graphite Project Graphite=0.9.10
Remediation
Event History
Sep 27, 2013
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Data Sourced
via NVD·10:08 AM
RemedyDescriptionSeverityWeaknessAffected Software
May 17, 2022
Advisory Published
05:03 AM
Frequently Asked Questions
1
What is the severity of CVE-2013-5942?
CVE-2013-5942 is considered a critical vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2013-5942?
To fix CVE-2013-5942, upgrade Graphite to version 0.9.11 or later.
3
Which versions of Graphite are affected by CVE-2013-5942?
CVE-2013-5942 affects Graphite versions 0.9.5 through 0.9.10.
4
What type of vulnerability is CVE-2013-5942?
CVE-2013-5942 is a remote code execution vulnerability due to unsafe usage of the pickle Python module.
5
Are there any workarounds for CVE-2013-5942?
There are no effective workarounds for CVE-2013-5942; upgrading to a secure version is recommended.