Security Advisory

CVE-2019-17206

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2019-10-05 22:01:24
Last updated 2024-08-05 01:33:17
Assigner mitre
State PUBLISHED

Description

Uncontrolled deserialization of a pickled object in models.py in Frost Ming rediswrapper (aka Redis Wrapper) before 0.3.0 allows attackers to execute arbitrary scripts.