CVE-2018-3650: Input Validation
Published Aug 1, 2018
·Updated
Insufficient Input Validation in Bleach module in INTEL Distribution for Python versions prior to IDP 2018 Update 2 allows unprivileged user to bypass URI sanitization via local vector.
Affected Software
3 affected components
Intel Distribution for Python<2018
Intel Distribution for Python=2018-update_1
Intel Distribution for Python=2018-update_2
Event History
Aug 1, 2018
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2018-3650?
CVE-2018-3650 is a vulnerability in the Bleach module in Intel Distribution for Python that allows an unprivileged user to bypass URI sanitization via a local vector.
2
What software versions are affected by CVE-2018-3650?
CVE-2018-3650 affects Intel Distribution for Python versions prior to IDP 2018 Update 2.
3
What is the severity of CVE-2018-3650?
CVE-2018-3650 has a severity score of 7.8, which is considered high.
4
How can an unprivileged user bypass URI sanitization in Intel Distribution for Python?
An unprivileged user can bypass URI sanitization in Intel Distribution for Python by exploiting the vulnerability in the Bleach module.
5
Is there a fix available for CVE-2018-3650?
Yes, a fix for CVE-2018-3650 is available in Intel Distribution for Python 2018 Update 2.