Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:29916
HistoryApr 06, 2021 - 7:56 a.m.

Arbitrary File Read

2021-04-0607:56:22
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
16
python3.5
vulnerability
arbitrary file read
pydoc
local users
extract files
getfile url
file system.

EPSS

0.001

Percentile

26.2%

python3.5 is vulnerable to arbitrary file read. Running pydoc -p allows other local users to extract arbitrary files. The /getfile?key=path URL allows to read arbitrary file on the file system.

References