HIGH
Arbitrary Code Generation
Published Aug 14, 2020
8.8
HIGHCVSS 4.0
EPSS 1.85%
Description
In openapi-python-client before version 0.5.3, clients generated with a maliciously crafted OpenAPI Document can generate arbitrary Python code. Subsequent execution of this malicious client is arbitrary code execution.
Affected products
-
Affected
- < 0.5.3
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Triaxtec | Openapi-Python-Client | unknown | Affected
|
- < 0.5.3
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (10)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-0122 Advisory
- https://github.com/advisories/GHSA-9x4c-63pf-525f Advisory
- https://github.com/openapi-generators/openapi-python-client/commit/f7a56aae32cba823a77a84a1f10400799b19c19a
- https://github.com/openapi-generators/openapi-python-client/releases/tag/v.0.5.3
- https://github.com/pypa/advisory-database/tree/main/vulns/openapi-python-client/PYSEC-2020-71.yaml
- https://github.com/triaxtec/openapi-python-client/blob/main/CHANGELOG.md#053---2020-08-13 x_refsource_MISCRelease NotesThird Party Advisory
- https://github.com/triaxtec/openapi-python-client/commit/f7a56aae32cba823a77a84a1f10400799b19c19a x_refsource_MISCPatchThird Party Advisory
- https://github.com/triaxtec/openapi-python-client/security/advisories/GHSA-9x4c-63pf-525f x_refsource_CONFIRMThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-15142
- https://pypi.org/project/openapi-python-client x_refsource_MISCProductThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-0122 | Advisory | |
| https://github.com/advisories/GHSA-9x4c-63pf-525f | Advisory | |
| https://github.com/openapi-generators/openapi-python-client/commit/f7a56aae32cba823a77a84a1f10400799b19c19a | ||
| https://github.com/openapi-generators/openapi-python-client/releases/tag/v.0.5.3 | ||
| https://github.com/pypa/advisory-database/tree/main/vulns/openapi-python-client/PYSEC-2020-71.yaml | ||
| https://github.com/triaxtec/openapi-python-client/blob/main/CHANGELOG.md#053---2020-08-13 | x_refsource_MISCRelease NotesThird Party Advisory | |
| https://github.com/triaxtec/openapi-python-client/commit/f7a56aae32cba823a77a84a1f10400799b19c19a | x_refsource_MISCPatchThird Party Advisory | |
| https://github.com/triaxtec/openapi-python-client/security/advisories/GHSA-9x4c-63pf-525f | x_refsource_CONFIRMThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2020-15142 | ||
| https://pypi.org/project/openapi-python-client | x_refsource_MISCProductThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Aug 14, 2020
Updated Aug 4, 2024
Reserved Jun 25, 2020
Link CVE-2020-15142
CISA Vulnrichment
No data
Red Hat
No data
GitHub
Link GHSA-9X4C-63PF-525F