Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:5406
HistoryNov 10, 2017 - 11:51 p.m.

Remote Code Execution (RCE)

2017-11-1023:51:26
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
2

0.022 Low

EPSS

Percentile

89.5%

confire is vulnerable to remote code execution attacks. The attacks can happen because the config.py file allows users to parse their configuration from the /.confire.yaml through the yaml.load() function of the YAML parser, allowing attackers to inject and execute arbitrary python commands.

CPENameOperatorVersion
confirele0.2.0

0.022 Low

EPSS

Percentile

89.5%

Related for VERACODE:5406