CVE-2018-3650

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
01/08/2018
Last modified:
19/11/2018

Description

Insufficient Input Validation in Bleach module in INTEL Distribution for Python versions prior to IDP 2018 Update 2 allows unprivileged user to bypass URI sanitization via local vector.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:intel:distribution_for_python:*:*:*:*:*:*:*:* 2018 (excluding)
cpe:2.3:a:intel:distribution_for_python:2018:update_1:*:*:*:*:*:*
cpe:2.3:a:intel:distribution_for_python:2018:update_2:*:*:*:*:*:*