REDHAT-BUG-2478170: Python jsonpickle vulnerability
python jsonpickle 2.0.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary Python commands by deserializing malicious JSON payloads containing py/repr objects. Attackers can craft JSON strings with py/repr directives that invoke the eval function during deserialization to execute system commands and arbitrary code.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2478170?
The severity of REDHAT-BUG-2478170 is rated at 89, indicating a high risk associated with this vulnerability.
What type of vulnerability is REDHAT-BUG-2478170?
REDHAT-BUG-2478170 is a remote code execution vulnerability that affects Python jsonpickle version 2.0.0.
How can attackers exploit REDHAT-BUG-2478170?
Attackers can exploit REDHAT-BUG-2478170 by deserializing malicious JSON payloads containing py/repr objects that invoke the eval function.
What is the impact of REDHAT-BUG-2478170?
The impact of REDHAT-BUG-2478170 allows attackers to execute arbitrary Python commands on affected systems.
How do I fix REDHAT-BUG-2478170?
To fix REDHAT-BUG-2478170, you should upgrade to a version of Python jsonpickle that addresses the vulnerability.