QID 980778
QID 980778: Python (pip) Security Update for pyro (GHSA-xrr4-74mc-rpjc)
pyro before 3.15 unsafely handles pid files in temporary directory locations and opening the pid file as root. An attacker can use this flaw to overwrite arbitrary files via symlinks.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-xrr4-74mc-rpjc for updates pertaining to this vulnerability.
Vendor References
- GHSA-xrr4-74mc-rpjc -
github.com/advisories/GHSA-xrr4-74mc-rpjc
CVEs related to QID 980778
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-xrr4-74mc-rpjc | pyro |
|