Back

CRITICAL

python-reportlab: code injection in colors.py allows attacker to execute code

Published Oct 16, 2019

Description

ReportLab through 3.5.26 allows remote code execution because of toColor(eval(arg)) in colors.py, as demonstrated by a crafted XML document with '<span color="' followed by arbitrary Python code.

Affected products

Remediation

Red Hat statement

This vulnerability will not be fixed in Red Hat Quay because it only affects a non-supported feature which is disabled behind a feature flag.

Red Hat mitigation

No known mitigation available.

Weaknesses (2)

References (26)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Oct 16, 2019
Updated Aug 5, 2024
Reserved Oct 16, 2019
CISA Vulnrichment
Updated Jul 19, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Oct 16, 2019
ENISA EUVD
Assigner mitre
Published Oct 16, 2019
Updated Aug 5, 2024
Exploited since n/a
EUVD-2019-0122 GHSA-QPG2-VX7J-3869