CVE-2020-15271
Summary
| CVE | CVE-2020-15271 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-10-26 18:15:00 UTC |
| Updated | 2020-11-13 16:40:00 UTC |
| Description | In lookatme (python/pypi package) versions prior to 2.3.0, the package automatically loaded the built-in "terminal" and "file_loader" extensions. Users that use lookatme to render untrusted markdown may have malicious shell commands automatically run on their system. This is fixed in version 2.3.0. As a workaround, the `lookatme/contrib/terminal.py` and `lookatme/contrib/file_loader.py` files may be manually deleted. Additionally, it is always recommended to be aware of what is being rendered with lookatme. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| lookatme · PyPI |
MISC |
pypi.org |
Release Notes, Third Party Advisory |
| Markdown-supplied Shell Command Execution · Advisory · d0c-s4vage/lookatme · GitHub |
CONFIRM |
github.com |
Third Party Advisory |
| Adds warnings about loading extensions by d0c-s4vage · Pull Request #110 · d0c-s4vage/lookatme · GitHub |
MISC |
github.com |
Exploit, Third Party Advisory |
| Release v2.3.0 · d0c-s4vage/lookatme · GitHub |
MISC |
github.com |
Release Notes, Third Party Advisory |
| Merge pull request #110 from d0c-s4vage/feature/109-extension_warnings · d0c-s4vage/lookatme@72fe36b · GitHub |
MISC |
github.com |
Patch, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 983215 Python (pip) Security Update for lookatme (GHSA-c84h-w6cr-5v8q)