Back

MEDIUM

python-beaker: Deserialization of Untrusted Data which can lead to Arbitrary code execution

Published Jun 26, 2020

Description

The Beaker library through 1.11.0 for Python is affected by deserialization of untrusted data, which could lead to arbitrary code execution.

Affected products

Remediation

Red Hat mitigation

Implementing proper access control on the Beaker cache database, to prevent unauthorized writes into the database, will mitigate exploitation of this flaw. This flaw also cannot be triggered if the Cache functionality of Beaker is not used. When using the Session feature of Beaker, use the signing functionality to verify the integrity of the data retrieved from the database before deserialization.

Metrics

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jun 26, 2020
Updated Aug 6, 2024
Reserved Jun 26, 2020
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date May 14, 2020
GHSA-3CWM-7JMM-774W