Do your applications use this vulnerable package?
Test your applications
Overview
Affected versions of this package are vulnerable to CVE-2020-27619. In Python 3 through 3.9.0, the Lib/test/multibytecodec_support.py CJK codec tests call eval() on content retrieved via HTTP.
Remediation
There is no fixed version for python3.7
.
References
CVSS Score
9.8
low severity
-
Attack VectorNetwork
-
Attack ComplexityLow
-
Privileges RequiredNone
-
User InteractionNone
-
ScopeUnchanged
-
ConfidentialityHigh
-
IntegrityHigh
-
AvailabilityHigh
- CVE
- CVE-2020-27619
- Snyk ID
- SNYK-DEBIAN10-PYTHON37-1021148
- Disclosed
- 22 Oct, 2020
- Published
- 23 Oct, 2020