Command injection in Tablib - CVE-2017-2810
Published: June 16, 2017
Vulnerability details
The vulnerability exists in the Databook loading functionality of Tablib due to command injection flaw. A remote attacker can insert python into loaded yaml, inject python commands and execute arbitrary code.
Successful exploitation of the vulnerability may result in full system compromise.
Affected software
Gentoo Linux
Fedora
python-tablib
How to mitigate CVE-2017-2810
Cybersecurity Help is currently unaware of any official patch addressing the vulnerability.