{"id":"GHSA-gcr6-rf47-jrgf","summary":"Loaded Databook of Tablib prone to python insertion resulting in command execution","details":"An exploitable vulnerability exists in the Databook loading functionality of Tablib 0.11.4. A yaml loaded Databook can execute arbitrary python commands resulting in command execution. An attacker can insert python into loaded yaml to trigger this vulnerability.","aliases":["CVE-2017-2810","PYSEC-2017-95"],"modified":"2024-12-07T05:39:28.757639Z","published":"2018-07-13T16:01:25Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2020-06-16T21:36:54Z","nvd_published_at":"2017-06-14T13:29:00Z","cwe_ids":[],"severity":"CRITICAL"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2017-2810"},{"type":"WEB","url":"https://github.com/jazzband/tablib/commit/69abfc3ada5d754cb152119c0b4777043657cb6e"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-gcr6-rf47-jrgf"},{"type":"PACKAGE","url":"https://github.com/jazzband/tablib"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/tablib/PYSEC-2017-95.yaml"},{"type":"WEB","url":"https://security.gentoo.org/glsa/201811-18"},{"type":"WEB","url":"https://talosintelligence.com/vulnerability_reports/TALOS-2017-0307"}],"affected":[{"package":{"name":"tablib","ecosystem":"PyPI","purl":"pkg:pypi/tablib"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.11.5"}]}],"versions":["0.0.1","0.10.0","0.11.0","0.11.1","0.11.2","0.11.3","0.11.4","0.6.1","0.6.2","0.6.3","0.6.4","0.7.0","0.7.1","0.8.0","0.8.1","0.8.2","0.8.3","0.8.4","0.9.0","0.9.1","0.9.10","0.9.11","0.9.2","0.9.3","0.9.4","0.9.5","0.9.6","0.9.7","0.9.8","0.9.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/07/GHSA-gcr6-rf47-jrgf/GHSA-gcr6-rf47-jrgf.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}