CVE-2018-14572
28.08.2018, 19:29
In conference-scheduler-cli, a pickle.load call on imported data allows remote attackers to execute arbitrary code via a crafted .pickle file, as demonstrated by Python code that contains an os.system call.
Vendor | Product | Version |
---|---|---|
pyconuk | conference-scheduler-cli | 𝑥 ≤ 0.10.1 |
𝑥
= Vulnerable software versions
References