CVE-2019-9710
12.03.2019, 02:29
An issue was discovered in webargs before 5.1.3, as used with marshmallow and other products. JSON parsing uses a short-lived cache to store the parsed JSON body. This cache is not thread-safe, meaning that incorrect JSON payloads could have been parsed for concurrent requests.
Vendor | Product | Version |
---|---|---|
webargs_project | webargs | 𝑥 < 5.1.3 |
𝑥
= Vulnerable software versions