CVE-2019-15149
Severity CVSS v4.0:
Pending analysis
Type:
CWE-254
Security Features
Publication date:
18/08/2019
Last modified:
05/08/2024
Description
core.py in Mitogen before 0.2.8 has a typo that drops the unidirectional-routing protection mechanism in the case of a child that is initiated by another child. The Ansible extension is unaffected. NOTE: the vendor disputes this issue because it is exploitable only in conjunction with hypothetical other factors, i.e., an affected use case within a library caller, and a bug in the message receiver policy code that led to reliance on this extra protection mechanism
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Base Score 2.0
6.80
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:networkgenomics:mitogen:*:*:*:*:*:*:*:* | 0.2.8 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



