CVE Vulnerabilities

CVE-2017-2810

Published: Jun 14, 2017 | Modified: Apr 19, 2022
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
7.5 LOW
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Ubuntu
LOW

An exploitable vulnerability exists in the Databook loading functionality of Tablib 0.11.4. A yaml loaded Databook can execute arbitrary python commands resulting in command execution. An attacker can insert python into loaded yaml to trigger this vulnerability.

Affected Software

Name Vendor Start Version End Version
Tablib Python 0.11.4 (including) 0.11.4 (including)
Python-tablib Ubuntu artful *
Python-tablib Ubuntu trusty *
Python-tablib Ubuntu upstream *
Python-tablib Ubuntu xenial *
Python-tablib Ubuntu yakkety *
Python-tablib Ubuntu zesty *

References