Developer Tools & Libraries

Remote Code Execution

Remote Code Execution In JsonPickle Python Module

Remote Code Execution in jsonPickle python module jsonpickle <= 1.4.2 versions allows remote code execution during deserialization of a malicious payload through the decode() function.

9.8
/ 10
Critical
CVSS v3.1
ADVISORY ID
PS47
PUBLISHED
2022-10-03
CVE IDs
CVE-2020-22083, CVE-2021-35951
VENDORS
jsonpickle (David Aguilar)
PUBLIC EXPLOIT
PoC public
CWE
CWE-502
PRODUCT
jsonpickle <= 1.4.2
CVSS VECTOR
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Abstract blurred background with dark tones and smooth gradient waves of blue, purple, and orange hues.
Summary

Overview

Remote Code Execution in jsonPickle python module

jsonpickle <= 1.4.2 versions allows remote code execution during deserialization of a malicious payload through the decode() function.

Vulnerability details

Vulnerability details

CVE-2020-22083
CWE-502
Critical | 9.8

Remote Code Execution in jsonPickle python module jsonpickle <= 1.4.2 versions allows remote code execution during deserialization of a malicious payload through the decode() function.

Auth:
None (remote)
Impact:
Sensitive data disclosure, arbitrary data or code modification, denial of service
CVE-2021-35951
High | 7.5
Impact:
Denial of service
DISCLOSURE

Disclosure timeline

2020-08-13 reported to the vendor

2020-12-17 CVE published

Credits

Manmeet Singh