pandas through 1.0.3 can unserialize and execute commands from an untrusted file that is passed to the read_pickle() function, if __reduce__ makes an os.system call. NOTE: third parties dispute this issue because the read_pickle() function is documented as unsafe and it is the user's responsibility to use the function in a secure manner
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T12:11:19.086Z
Reserved: 2020-05-15T00:00:00
Link: CVE-2020-13091
No data.
Status : Modified
Published: 2020-05-15T19:15:12.167
Modified: 2024-11-21T05:00:38.950
Link: CVE-2020-13091
No data.
OpenCVE Enrichment
No data.
Weaknesses