Lucene search

K
nvd[email protected]NVD:CVE-2011-4212
HistoryOct 30, 2011 - 7:55 p.m.

CVE-2011-4212

2011-10-3019:55:01
CWE-264
web.nvd.nist.gov
10

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

AI Score

6.9

Confidence

Low

EPSS

0.002

Percentile

64.5%

The sandbox environment in the Google App Engine Python SDK before 1.5.4 does not properly prevent os.popen calls, which allows local users to bypass intended access restrictions and execute arbitrary commands via a dev_appserver.RestrictedPathFunction._original_os reference within the code parameter to _ah/admin/interactive/execute, a different vulnerability than CVE-2011-1364.

Affected configurations

Nvd
Node
googleapp_engine_python_sdkRange1.5.3
OR
googleapp_engine_python_sdkMatch1.0.1
OR
googleapp_engine_python_sdkMatch1.0.2
OR
googleapp_engine_python_sdkMatch1.1.0
OR
googleapp_engine_python_sdkMatch1.1.1
OR
googleapp_engine_python_sdkMatch1.1.2
OR
googleapp_engine_python_sdkMatch1.1.3
OR
googleapp_engine_python_sdkMatch1.1.4
OR
googleapp_engine_python_sdkMatch1.1.5
OR
googleapp_engine_python_sdkMatch1.1.6
OR
googleapp_engine_python_sdkMatch1.1.7
OR
googleapp_engine_python_sdkMatch1.1.8
OR
googleapp_engine_python_sdkMatch1.1.9
OR
googleapp_engine_python_sdkMatch1.2.0
OR
googleapp_engine_python_sdkMatch1.2.1
OR
googleapp_engine_python_sdkMatch1.2.2
OR
googleapp_engine_python_sdkMatch1.2.3
OR
googleapp_engine_python_sdkMatch1.2.4
OR
googleapp_engine_python_sdkMatch1.2.5
OR
googleapp_engine_python_sdkMatch1.2.6
OR
googleapp_engine_python_sdkMatch1.2.7
OR
googleapp_engine_python_sdkMatch1.3.0
OR
googleapp_engine_python_sdkMatch1.3.1
OR
googleapp_engine_python_sdkMatch1.3.2
OR
googleapp_engine_python_sdkMatch1.3.3
OR
googleapp_engine_python_sdkMatch1.3.4
OR
googleapp_engine_python_sdkMatch1.3.5
OR
googleapp_engine_python_sdkMatch1.3.6
OR
googleapp_engine_python_sdkMatch1.3.7
OR
googleapp_engine_python_sdkMatch1.3.8
OR
googleapp_engine_python_sdkMatch1.4.0
OR
googleapp_engine_python_sdkMatch1.4.1
OR
googleapp_engine_python_sdkMatch1.4.2
OR
googleapp_engine_python_sdkMatch1.4.3
OR
googleapp_engine_python_sdkMatch1.5.0
OR
googleapp_engine_python_sdkMatch1.5.1
OR
googleapp_engine_python_sdkMatch1.5.2
VendorProductVersionCPE
googleapp_engine_python_sdk*cpe:2.3:a:google:app_engine_python_sdk:*:*:*:*:*:*:*:*
googleapp_engine_python_sdk1.0.1cpe:2.3:a:google:app_engine_python_sdk:1.0.1:*:*:*:*:*:*:*
googleapp_engine_python_sdk1.0.2cpe:2.3:a:google:app_engine_python_sdk:1.0.2:*:*:*:*:*:*:*
googleapp_engine_python_sdk1.1.0cpe:2.3:a:google:app_engine_python_sdk:1.1.0:*:*:*:*:*:*:*
googleapp_engine_python_sdk1.1.1cpe:2.3:a:google:app_engine_python_sdk:1.1.1:*:*:*:*:*:*:*
googleapp_engine_python_sdk1.1.2cpe:2.3:a:google:app_engine_python_sdk:1.1.2:*:*:*:*:*:*:*
googleapp_engine_python_sdk1.1.3cpe:2.3:a:google:app_engine_python_sdk:1.1.3:*:*:*:*:*:*:*
googleapp_engine_python_sdk1.1.4cpe:2.3:a:google:app_engine_python_sdk:1.1.4:*:*:*:*:*:*:*
googleapp_engine_python_sdk1.1.5cpe:2.3:a:google:app_engine_python_sdk:1.1.5:*:*:*:*:*:*:*
googleapp_engine_python_sdk1.1.6cpe:2.3:a:google:app_engine_python_sdk:1.1.6:*:*:*:*:*:*:*
Rows per page:
1-10 of 371

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

AI Score

6.9

Confidence

Low

EPSS

0.002

Percentile

64.5%

Related for NVD:CVE-2011-4212