Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:46764
HistoryMay 06, 2024 - 11:52 a.m.

Code Injection

2024-05-0611:52:57
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
3
code injection
vulnerability
tqdm
cli
python
eval function
arbitrary code

4.8 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L

7.6 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

15.8%

tqdm is vulnerable to Code Injection. The vulnerability is due to the handling of optional non-boolean CLI arguments such as --delim, --buf-size, --manpath which get passed through python’s eval function without proper sanitization. An attacker can execute arbitrary code by injecting malicious input into these arguments.

4.8 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L

7.6 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

15.8%