7.5

CVE-2019-16328

Exploit
In RPyC 4.1.x through 4.1.1, a remote attacker can dynamically modify object attributes to construct a remote procedure call that executes code for an RPyC service with default configuration settings.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Rpyc ProjectRpyc Version >= 4.1.0 <= 4.1.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 13.05% 0.958
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N
CWE-1321 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.

http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00046.html
Broken Link
http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00004.html
Broken Link
https://github.com/tomerfiliba/rpyc
Third Party Advisory
Product
https://rpyc.readthedocs.io/en/latest/docs/security.html
Vendor Advisory
Exploit