GHSA-22mf-97vh-x8rw
Dashboard / Vulnerabilities / GHSA-22mf-97vh-x8rw
GHSA-22mf-97vh-x8rw
Summary: Deserialization vulnerability exists in parso
Details: ** DISPUTED ** A deserialization vulnerability exists in the way parso through 0.4.0 handles grammar parsing from the cache. Cache loading relies on pickle and, provided that an evil pickle can be written to a cache grammar file and that its parsing can be triggered, this flaw leads to Arbitrary Code Execution. NOTE: This is disputed because "the cache directory is not under control of the attacker in any common configuration."
References: https://nvd.nist.gov/vuln/detail/CVE-2019-12760, https://github.com/davidhalter/parso/issues/75, https://gist.github.com/dhondta/f71ae7e5c4234f8edfd2f12503a5dcc7, https://github.com/advisories/GHSA-22mf-97vh-x8rw, https://github.com/davidhalter/parso, https://github.com/pypa/advisory-database/tree/main/vulns/parso/PYSEC-2019-109.yaml
Affected packages
Package
Name: parso
Purl: pkg:pypi/parso
Affected ranges
Type: ECOSYSTEM
Events:
