Command injection in Tablib - CVE-2017-2810
Published: June 16, 2017
Tablib
Detailed vulnerability description
The vulnerability exists in the Databook loading functionality of Tablib due to command injection flaw. A remote attacker can insert python into loaded yaml, inject python commands and execute arbitrary code.
Successful exploitation of the vulnerability may result in full system compromise.
How to mitigate CVE-2017-2810
Cybersecurity Help is currently unaware of any official patch addressing the vulnerability.