{"api_version":"1","generated_at":"2026-07-23T06:09:53+00:00","cve":"CVE-2017-20052","urls":{"html":"https://cve.report/CVE-2017-20052","api":"https://cve.report/api/cve/CVE-2017-20052.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-20052","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-20052"},"summary":{"title":"CVE-2017-20052","description":"A vulnerability classified as problematic was found in Python 2.7.13. This vulnerability affects unknown code of the component pgAdmin4. The manipulation leads to uncontrolled search path. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.","state":"PUBLIC","assigner":"cna@vuldb.com","published_at":"2022-06-16 07:15:00","updated_at":"2022-11-05 02:27:00"},"problem_types":["CWE-427"],"metrics":[],"references":[{"url":"http://seclists.org/fulldisclosure/2017/Feb/92","name":"http://seclists.org/fulldisclosure/2017/Feb/92","refsource":"MISC","tags":[],"title":"Full Disclosure: Python + PostgreSQL pgAdmin4 – Insecure Library Loading Allows Code Execution","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://vuldb.com/?id.97822","name":"https://vuldb.com/?id.97822","refsource":"MISC","tags":[],"title":"CVE-2017-20052 | Python pgAdmin4 uncontrolled search path","mime":"text/html","httpstatus":"429","archivestatus":"404"},{"url":"https://security.netapp.com/advisory/ntap-20220804-0005/","name":"https://security.netapp.com/advisory/ntap-20220804-0005/","refsource":"CONFIRM","tags":[],"title":"CVE-2017-20052 Python Vulnerability in NetApp Products | NetApp Product Security","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-20052","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-20052","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"20052","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"python","cpe5":"python","cpe6":"2.7.13","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ID":"CVE-2017-20052","TITLE":"Python pgAdmin4 uncontrolled search path","REQUESTER":"cna@vuldb.com","ASSIGNER":"cna@vuldb.com","STATE":"PUBLIC"},"generator":"vuldb.com","affects":{"vendor":{"vendor_data":[{"vendor_name":"","product":{"product_data":[{"product_name":"Python","version":{"version_data":[{"version_value":"2.7.13"}]}}]}}]}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-427 Uncontrolled Search Path"}]}]},"description":{"description_data":[{"lang":"eng","value":"A vulnerability classified as problematic was found in Python 2.7.13. This vulnerability affects unknown code of the component pgAdmin4. The manipulation leads to uncontrolled search path. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used."}]},"credit":"Karn Ganeshen","impact":{"cvss":{"version":"3.1","baseScore":"5.0","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L"}},"references":{"reference_data":[{"url":"http://seclists.org/fulldisclosure/2017/Feb/92","refsource":"MISC","name":"http://seclists.org/fulldisclosure/2017/Feb/92"},{"url":"https://vuldb.com/?id.97822","refsource":"MISC","name":"https://vuldb.com/?id.97822"},{"refsource":"CONFIRM","name":"https://security.netapp.com/advisory/ntap-20220804-0005/","url":"https://security.netapp.com/advisory/ntap-20220804-0005/"}]}},"nvd":{"publishedDate":"2022-06-16 07:15:00","lastModifiedDate":"2022-11-05 02:27:00","problem_types":["CWE-427"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:L/AC:M/Au:N/C:P/I:P/A:P","accessVector":"LOCAL","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":4.4},"severity":"MEDIUM","exploitabilityScore":3.4,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:python:python:2.7.13:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":null,"notes":[]}}}