CVE-2017-2810: Critical severity tablib vulnerability
An exploitable vulnerability exists in the Databook loading functionality of Tablib 0.11.4. A yaml loaded Databook can execute arbitrary python commands resulting in command execution. An attacker can insert python into loaded yaml to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-2810?
CVE-2017-2810 is rated as high severity due to its ability to execute arbitrary python commands through a loaded yaml file.
How does CVE-2017-2810 allow for command execution?
CVE-2017-2810 allows command execution by allowing an attacker to insert malicious python code into the yaml data loaded into a Databook.
What software is affected by CVE-2017-2810?
CVE-2017-2810 specifically affects Tablib version 0.11.4.
How can I mitigate the risks associated with CVE-2017-2810?
To mitigate risks from CVE-2017-2810, avoid using Tablib version 0.11.4 and update to a patched version.
Is there a patch available for CVE-2017-2810?
Yes, a patch addressing CVE-2017-2810 is available in later versions of Tablib.