CVE-2017-2810
HIGHTablib 0.11.4 - Remote Code Execution via YAML Databook Loading
Title source: llmDescription
An exploitable vulnerability exists in the Databook loading functionality of Tablib 0.11.4. A yaml loaded Databook can execute arbitrary python commands resulting in command execution. An attacker can insert python into loaded yaml to trigger this vulnerability.
References (3)
Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/99076
Third Party Advisory vendor-advisory
x_refsource_gentoo
https://security.gentoo.org/glsa/201811-18
Exploit, Third Party Advisory, VDB Entry x_refsource_misc
https://talosintelligence.com/vulnerability_reports/TALOS-2017-0307
Scores
CVSS v3
7.5
EPSS
0.0143
EPSS Percentile
80.9%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Details
Status
published
Products (3)
Kenneth Reitz/Tablib
0.11.4
pypi/tablib
0 - 0.11.5PyPI
python/tablib
0.11.4
Published
Jun 14, 2017
Tracked Since
Feb 18, 2026