Uncontrolled deserialization of a pickled object in rediswrapper allows attackers to execute arbitrary scripts
Critical severity
GitHub Reviewed
Published
Nov 20, 2019
to the GitHub Advisory Database
•
Updated Oct 26, 2024
Description
Reviewed
Nov 19, 2019
Published to the GitHub Advisory Database
Nov 20, 2019
Last updated
Oct 26, 2024
Uncontrolled deserialization of a pickled object in models.py in Frost Ming rediswrapper (aka Redis Wrapper) before 0.3.0 allows attackers to execute arbitrary scripts.
References