Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:3236
HistoryJan 05, 2017 - 3:28 a.m.

Arbitrary Code Execution

2017-01-0503:28:33
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
4

EPSS

0

Percentile

5.1%

tqdm is vulnerable to arbitrary code execution via insecure use of git. When importing tqdm, it will run a git log command to check if the user is running a pre-released version. It is possible for an attacker to create a repository in which git log executes arbitrary code.