CVE-2017-2810

HIGH

Tablib 0.11.4 - Remote Code Execution via YAML Databook Loading

Title source: llm
STIX 2.1

Description

An exploitable vulnerability exists in the Databook loading functionality of Tablib 0.11.4. A yaml loaded Databook can execute arbitrary python commands resulting in command execution. An attacker can insert python into loaded yaml to trigger this vulnerability.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/99076
Third Party Advisory vendor-advisory x_refsource_gentoo
https://security.gentoo.org/glsa/201811-18
Exploit, Third Party Advisory, VDB Entry x_refsource_misc
https://talosintelligence.com/vulnerability_reports/TALOS-2017-0307

Scores

CVSS v3 7.5
EPSS 0.0143
EPSS Percentile 80.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

Status published
Products (3)
Kenneth Reitz/Tablib 0.11.4
pypi/tablib 0 - 0.11.5PyPI
python/tablib 0.11.4
Published Jun 14, 2017
Tracked Since Feb 18, 2026