QID 980255
QID 980255: Python (pip) Security Update for babel (GHSA-h4m5-qpfp-3mpv)
Babel.Locale in Babel before 2.9.1 allows attackers to load arbitrary locale .dat files (containing serialized Python objects) via directory traversal, leading to code execution.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-h4m5-qpfp-3mpv for updates pertaining to this vulnerability.
Vendor References
- GHSA-h4m5-qpfp-3mpv -
github.com/advisories/GHSA-h4m5-qpfp-3mpv
CVEs related to QID 980255
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-h4m5-qpfp-3mpv | babel |
|