Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Configuration Injection via Carriage Return (\r) in write() method
Vulnerability Description
When using the "configparser" module to write configuration files containing multi-line text values with carriage return characters (\r) the resulting file could be injected with unexpected keys and values if the attacker controls the written value.
CVSS Information
CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Vulnerability Type
N/A
Vulnerability Title
Python 输入验证错误漏洞
Vulnerability Description
Python Software Foundation CPython是Python Software Foundation基金会的编程语言解释器。 Python 3.15.0之前版本存在输入验证错误漏洞,该漏洞源于使用“configparser”模块写入包含回车字符(\r)的多行文本值的配置文件时,若攻击者控制写入值,可能注入意外键和值。
CVSS Information
N/A
Vulnerability Type
N/A