QID 997082
Date Published: 2024-02-02
QID 997082: Python (Pip) Security Update for jsonpickle (GHSA-j66q-qmrc-89rx)
jsonpickle through 1.4.1 allows remote code execution during deserialization of a malicious payload through the decode() function. This CVE is disputed by the project author as intended functionality.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-j66q-qmrc-89rx for updates and patch information.
Vendor References
- GHSA-j66q-qmrc-89rx -
github.com/advisories/GHSA-j66q-qmrc-89rx
CVEs related to QID 997082
Software Advisories
| Advisory ID | Software | Component | Link |
|---|