Jsonpickle是Jsonpickle个人开发者的一款基于Python用于支持Python对象与Json进行序列化的软件。 jsonpickle 2.0.0版本存在代码注入漏洞,该漏洞源于反序列化问题,可能导致攻击者通过反序列化包含py/repr对象的恶意JSON有效载荷执行任意Python命令。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Jsonpickle | python jsonpickle | 2.0.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Jsonpickle | python jsonpickle | 2.0.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No comments yet