{"id":"GHSA-9ggp-4jpr-7ppj","summary":"Duplicate Advisory: Possible remote code execution via a remote procedure call","details":"Withdrawn: duplicate of GHSA-pj4g-4488-wmxm\n\n## Original Description\n\nIn RPyC 4.1.x through 4.1.1, a remote attacker can dynamically modify object attributes to construct a remote procedure call that executes code for an RPyC service with default configuration settings.","aliases":["CVE-2019-16328","GHSA-pj4g-4488-wmxm","PYSEC-2019-118"],"modified":"2024-12-06T05:39:36.478645Z","published":"2019-11-20T01:35:53Z","withdrawn":"2021-02-17T19:44:50Z","database_specific":{"github_reviewed_at":"2019-11-19T03:15:00Z","nvd_published_at":null,"cwe_ids":[],"severity":"HIGH","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-16328"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-9ggp-4jpr-7ppj"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-pj4g-4488-wmxm"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/rpyc/PYSEC-2019-118.yaml"},{"type":"WEB","url":"https://github.com/tomerfiliba/rpyc"},{"type":"WEB","url":"https://rpyc.readthedocs.io/en/latest/docs/security.html"},{"type":"WEB","url":"http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00046.html"},{"type":"WEB","url":"http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00004.html"}],"affected":[{"package":{"name":"rpyc","ecosystem":"PyPI","purl":"pkg:pypi/rpyc"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.1.0"},{"fixed":"4.1.2"}]}],"versions":["4.1.0","4.1.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/11/GHSA-9ggp-4jpr-7ppj/GHSA-9ggp-4jpr-7ppj.json"}}],"schema_version":"1.9.0"}