ZeroHour

CVE-2022-35411

PoC ×3
CVSS 3.1
9.8 critical
EPSS
46%p99
Published
()
Modified
Description

rpc.py through 0.6.0 allows Remote Code Execution because an unpickle occurs when the "serializer: pickle" HTTP header is sent. In other words, although JSON (not Pickle) is the default data format, an unauthenticated client can cause the data to be processed with unpickle.

Vendors
rpc.py project
Products
rpc.py
Weakness
CWE-522
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.