CVE-2020-27619 - log back

CVE-2020-27619 edited at 26 Mar 2021 17:30:33
Severity
- Medium
+ High
CVE-2020-27619 edited at 16 Mar 2021 11:18:34
Severity
- Unknown
+ Medium
Remote
- Unknown
+ Remote
Type
- Unknown
+ Arbitrary code execution
Description
+ In Python 3 through 3.9.0, the Lib/test/multibytecodec_support.py CJK codec tests call eval() on content retrieved via HTTP.
References
+ https://python-security.readthedocs.io/vuln/cjk-codec-download-eval.html
+ https://bugs.python.org/issue41944
+ https://github.com/python/cpython/pull/22575
+ https://github.com/python/cpython/commit/b664a1df4ee71d3760ab937653b10997081b1794
CVE-2020-27619 created at 16 Mar 2021 11:15:12
Severity
+ Unknown
Remote
+ Unknown
Type
+ Unknown
Description
References
Notes