CVE-2018-17175

MEDIUM

Marshmallow <2.15.1, 3.x <3.0.0b9 - Info Disclosure

Title source: llm
STIX 2.1

Description

In the marshmallow library before 2.15.1 and 3.x before 3.0.0b9 for Python, the schema "only" option treats an empty list as implying no "only" option, which allows a request that was intended to expose no fields to instead expose all fields (if the schema is being filtered dynamically using the "only" option, and there is a user role that produces an empty value for "only").

References (3)

Core 3
Core References
Third Party Advisory x_refsource_misc
https://github.com/marshmallow-code/marshmallow/pull/777
Third Party Advisory x_refsource_misc
https://github.com/marshmallow-code/marshmallow/pull/782
Issue Tracking, Third Party Advisory x_refsource_misc
https://github.com/marshmallow-code/marshmallow/issues/772

Scores

CVSS v3 5.3
EPSS 0.0186
EPSS Percentile 77.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

Status published
Products (3)
marshmallow_project/marshmallow < 2.15.1
marshmallow_project/marshmallow 3.0 - 3.0.0b9
pypi/marshmallow 0 - 2.15.1PyPI
Published Sep 18, 2018
Tracked Since Feb 18, 2026