QID 995467
Date Published: 2023-10-03
QID 995467: Python (Pip) Security Update for pydash (GHSA-8mjr-6c96-39w8)
This affects versions of the package pydash before 6.0.0. A number of pydash methods such as pydash.objects.invoke() and pydash.collections.invoke_map() accept dotted paths (Deep Path Strings) to target a nested Python object, relative to the original source object. These paths can be used to target internal class attributes and dict items, to retrieve, modify or invoke nested Python objects.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-8mjr-6c96-39w8 for updates and patch information.
Vendor References
- GHSA-8mjr-6c96-39w8 -
github.com/advisories/GHSA-8mjr-6c96-39w8
CVEs related to QID 995467
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-8mjr-6c96-39w8 | pydash |
|