QID 981131
QID 981131: Python (pip) Security Update for conference-scheduler-cli (GHSA-cf3c-fffp-34qh)
In conference-scheduler-cli, a pickle.load call on imported data allows remote attackers to execute arbitrary code via a crafted .pickle file, as demonstrated by Python code that contains an os.system call.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-cf3c-fffp-34qh for updates pertaining to this vulnerability.
Vendor References
- GHSA-cf3c-fffp-34qh -
github.com/advisories/GHSA-cf3c-fffp-34qh
CVEs related to QID 981131
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-cf3c-fffp-34qh | conference-scheduler-cli |
|