QID 980896
QID 980896: Python (pip) Security Update for rope (GHSA-r38r-qp28-2m63)
base/oi/doa.py in the Rope library in CPython (aka Python) allows remote attackers to execute arbitrary code by leveraging an unsafe call to pickle.load.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-r38r-qp28-2m63 for updates pertaining to this vulnerability.
Vendor References
- GHSA-r38r-qp28-2m63 -
github.com/advisories/GHSA-r38r-qp28-2m63
CVEs related to QID 980896
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-r38r-qp28-2m63 | rope |
|