CVE-2019-17206

Publication date

2019-10-05 22:01:24

Family

mitre

State

PUBLISHED

Description

Uncontrolled deserialization of a pickled object in models.py in Frost Ming rediswrapper (aka Redis Wrapper) before 0.3.0 allows attackers to execute arbitrary scripts.