CVE-2013-5093
medium · 6.8The renderLocalView function in render/views.py in graphite-web in Graphite 0.9.5 through 0.9.10 uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via a crafted serialized object.
6.8
CVSS
38.7%
EPSS (exploit prob.)
99th
EPSS percentile
2013-09-27
Published
AV:N/AC:M/Au:N/C:P/I:P/A:P
Weaknesses
CWE-94
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| graphite_project | graphite | 0.9.5 |
| graphite_project | graphite | 0.9.6 |
| graphite_project | graphite | 0.9.7 |
| graphite_project | graphite | 0.9.8 |
| graphite_project | graphite | 0.9.9 |
| graphite_project | graphite | 0.9.10 |
Check a specific version with /api/v1/cve/match.
References
- http://ceriksen.com/2013/08/20/graphite-remote-code-execution-vulnerability-advisory/
- http://secunia.com/advisories/54556
- http://www.exploit-db.com/exploits/27752
- http://www.osvdb.org/96436
- http://www.securityfocus.com/bid/61894
- https://github.com/graphite-project/graphite-web/blob/master/docs/releases/0_9_11.rst
- https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/unix/webapp/graphite_pickle_exec.rb
- http://ceriksen.com/2013/08/20/graphite-remote-code-execution-vulnerability-advisory/
- http://secunia.com/advisories/54556
- http://www.exploit-db.com/exploits/27752
- http://www.osvdb.org/96436
- http://www.securityfocus.com/bid/61894
- https://github.com/graphite-project/graphite-web/blob/master/docs/releases/0_9_11.rst
- https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/unix/webapp/graphite_pickle_exec.rb
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2013-5093