CVE Vulnerabilities

CVE-2017-2810

Published: Jun 14, 2017 | Modified: Apr 20, 2025
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
7.5 LOW
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

An exploitable vulnerability exists in the Databook loading functionality of Tablib 0.11.4. A yaml loaded Databook can execute arbitrary python commands resulting in command execution. An attacker can insert python into loaded yaml to trigger this vulnerability.

Affected Software

NameVendorStart VersionEnd Version
TablibPython0.11.4 (including)0.11.4 (including)
Python-tablibUbuntuartful*
Python-tablibUbuntuesm-apps/xenial*
Python-tablibUbuntutrusty*
Python-tablibUbuntuupstream*
Python-tablibUbuntuxenial*
Python-tablibUbuntuyakkety*
Python-tablibUbuntuzesty*

References