QID 981624
QID 981624: Python (pip) Security Update for rediswrapper (GHSA-vrcf-g539-x6h3)
Uncontrolled deserialization of a pickled object in models.py in Frost Ming rediswrapper (aka Redis Wrapper) before 0.3.0 allows attackers to execute arbitrary scripts.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-vrcf-g539-x6h3 for updates pertaining to this vulnerability.
Vendor References
- GHSA-vrcf-g539-x6h3 -
github.com/advisories/GHSA-vrcf-g539-x6h3
CVEs related to QID 981624
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-vrcf-g539-x6h3 | rediswrapper |
|