Eve allows execution of arbitrary code
Critical severity
GitHub Reviewed
Published
Jul 12, 2018
to the GitHub Advisory Database
•
Updated Sep 20, 2024
Description
Published to the GitHub Advisory Database
Jul 12, 2018
Reviewed
Jun 16, 2020
Last updated
Sep 20, 2024
io/mongo/parser.py
in Eve (aka pyeve) before 0.7.5 allows remote attackers to execute arbitrary code via Code Injection in thewhere
parameter.References