CVE-2019-16328
Summary
| CVE | CVE-2019-16328 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-10-03 20:15:00 UTC |
| Updated | 2022-12-02 19:24:00 UTC |
| Description | In RPyC 4.1.x through 4.1.1, a remote attacker can dynamically modify object attributes to construct a remote procedure call that executes code for an RPyC service with default configuration settings. |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|
| Application |
Rpyc Project |
Rpyc |
All |
All |
All |
All |
References
| Reference | Source | Link | Tags |
|---|
| GitHub - tomerfiliba-org/rpyc: RPyC (Remote Python Call) - A transparent and symmetric RPC library for python |
MISC |
github.com |
Product, Third Party Advisory |
| Security — RPyC |
MISC |
rpyc.readthedocs.io |
Exploit, Vendor Advisory |
| [security-announce] openSUSE-SU-2020:0685-1: moderate: Security update f |
SUSE |
lists.opensuse.org |
|
| [security-announce] openSUSE-SU-2020:0763-1: moderate: Security update f |
SUSE |
lists.opensuse.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 980652 Python (pip) Security Update for rpyc (GHSA-pj4g-4488-wmxm)
- 982946 Python (pip) Security Update for rpyc (GHSA-9ggp-4jpr-7ppj)