{"id":"GHSA-74w3-2r77-fw5h","summary":"Use of Externally-Controlled Format String in consoleme","details":"A Python format string issue leading to information disclosure and potentially remote code execution in ConsoleMe for all versions prior to 1.2.2","aliases":["CVE-2022-27177","PYSEC-2022-189"],"modified":"2025-02-18T05:27:54.235204Z","published":"2022-04-03T00:00:58Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2022-04-05T17:54:33Z","nvd_published_at":"2022-04-01T23:15:00Z","cwe_ids":["CWE-134"],"severity":"CRITICAL"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-27177"},{"type":"WEB","url":"https://github.com/Netflix/consoleme/commit/2a3c84eee524d77c427b3329a8419cbbce9e1d16"},{"type":"PACKAGE","url":"https://github.com/Netflix/ConsoleMe"},{"type":"WEB","url":"https://github.com/Netflix/security-bulletins/blob/master/advisories/nflx-2022-001.md"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/consoleme/PYSEC-2022-189.yaml"}],"affected":[{"package":{"name":"consoleme","ecosystem":"PyPI","purl":"pkg:pypi/consoleme"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.2.2"}]}],"versions":["0.0.0","1.0.6.dev10","1.1.1","1.1.10.dev1","1.1.10.dev2","1.1.10.dev3","1.1.10.dev4","1.1.10.dev5","1.1.10.dev6","1.1.2","1.1.2.dev1","1.1.3","1.1.3.dev1","1.1.3.dev2","1.1.3.dev3","1.1.3.dev4","1.1.3.dev5","1.1.3.dev6","1.1.3.dev7","1.1.3.dev8","1.1.4","1.1.5","1.1.5.dev1","1.1.5.dev2","1.1.5.dev3","1.1.6","1.1.6.dev1","1.1.6.dev2","1.1.7","1.1.8","1.1.8.dev1","1.1.8.dev2","1.1.8.dev3","1.1.8.dev4","1.1.9","1.1.9.dev1","1.2.0","1.2.1","1.2.1.dev1","1.2.2.dev3","1.2.2.dev4"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/04/GHSA-74w3-2r77-fw5h/GHSA-74w3-2r77-fw5h.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}