CVE-2022-35411

Severity CVSS v4.0:
Pending analysis
Type:
CWE-522 Insufficiently Protected Credentials
Publication date:
08/07/2022
Last modified:
09/02/2024

Description

rpc.py through 0.6.0 allows Remote Code Execution because an unpickle occurs when the "serializer: pickle" HTTP header is sent. In other words, although JSON (not Pickle) is the default data format, an unauthenticated client can cause the data to be processed with unpickle.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:rpc.py_project:rpc.py:*:*:*:*:*:*:*:* 0.4.2 (including) 0.6.0 (including)