paraparser in ReportLab before 3.5.31 allows remote code execution because start_unichar in paraparser.py evaluates untrusted user input in a unichar element in a crafted XML document with '<unichar code="' followed by arbitrary Python code, a similar issue to CVE-2019-17626.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade python3-reportlab | Oct 23, 2023 | Sep 20, 2023 |
| Amazon Linux Ami 2 | — | Upgrade python-reportlabUpgrade python-reportlab-docsUpgrade python-reportlab-debuginfo | Oct 6, 2023 | Sep 20, 2023 |
| Centos_linux | — | Upgrade python-reportlab-debuginfoUpgrade python-reportlabUpgrade python-reportlab-docs | Oct 11, 2023 | Sep 20, 2023 |
| Debian | — | Upgrade python-reportlab | Oct 2, 2023 | Sep 20, 2023 |
| Huawei Euleros 2_0_sp5 | — | Upgrade python-reportlab | Oct 8, 2024 | Sep 20, 2023 |
| Oracle_linux | — | Upgrade python3-reportlabUpgrade python-reportlabUpgrade python-reportlab-docs | Oct 11, 2023 | Sep 20, 2023 |
| Redhat_linux | — | No solution existsUpgrade python-reportlab-debugsourceUpgrade python-reportlab-docsUpgrade python3-reportlab-debuginfoUpgrade python-reportlabUpgrade python3-reportlabUpgrade python-reportlab-debuginfo | Oct 11, 2023 | Sep 20, 2023 |
| Suse | — | Upgrade python3-reportlabUpgrade python-reportlab | Aug 9, 2024 | Sep 20, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub