paraparser in ReportLab before 3.5.31 allows remote code execution because start_unichar in paraparser.py evaluates untrusted user input in a unichar element in a crafted XML document with '<unichar code="' followed by arbitrary Python code, a similar issue to CVE-2019-17626.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade python3-reportlab | Oct 23, 2023 | Sep 20, 2023 |
| Amazon Linux Ami 2 | — | Upgrade python-reportlab-docsUpgrade python-reportlab-debuginfoUpgrade python-reportlab | Oct 6, 2023 | Sep 20, 2023 |
| Centos_linux | — | Upgrade python-reportlab-docsUpgrade python-reportlab-debuginfoUpgrade python-reportlab | Oct 11, 2023 | Sep 20, 2023 |
| Debian | — | Upgrade python-reportlab | Oct 2, 2023 | Sep 20, 2023 |
| Huawei Euleros 2_0_sp5 | — | Upgrade python-reportlab | Oct 8, 2024 | Sep 20, 2023 |
| Oracle_linux | — | Upgrade python3-reportlabUpgrade python-reportlabUpgrade python-reportlab-docs | Oct 11, 2023 | Sep 20, 2023 |
| Redhat_linux | — | Upgrade python3-reportlabUpgrade python-reportlab-debuginfoUpgrade python3-reportlab-debuginfoUpgrade python-reportlabUpgrade python-reportlab-debugsourceNo solution existsUpgrade python-reportlab-docs | Oct 11, 2023 | Sep 20, 2023 |
| Suse | — | Upgrade python3-reportlabUpgrade python-reportlab | Aug 9, 2024 | Sep 20, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub