First published: Fri Oct 15 2021(Updated: )
Ops CLI version 2.0.4 (and earlier) is affected by a Deserialization of Untrusted Data vulnerability to achieve arbitrary code execution when the `checkout_repo` function is called on a maliciously crafted file. An attacker can leverage this to execute arbitrary code on the victim machine.
Credit: psirt@adobe.com psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Ops-cli | <2.0.5 | |
pip/ops-cli | <=2.0.4 | 2.0.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.