QID 378603
QID 378603: Python Reportlab Library Remote Code Execution (RCE) Vulnerability
Reportlab is an Open Source project that allows the creation of documents in Portable Document Format (PDF) using the Python programming language.
CVE-2023-33733: Reportlab up to v3.6.12 allows attackers to execute arbitrary code via supplying a crafted PDF file.
Affected Versions:
Reportlab versions prior to v3.6.13
QID detection logic(Authenticated):
This QID checks for vulnerable versions of Reportlab library using the 'pip list' command.
Successful exploitation of this vulnerability may allow attackers to execute arbitrary code on the target system.
Solution
Customers are advised to update to Reportlab library version 3.6.13 or later. For more info please refer to Reportlab Changelog
Vendor References
- Reportlab Release Notes -
docs.reportlab.com/releases/notes/whats-new-3613/
CVEs related to QID 378603
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Reportlab Release Notes |
|