MGASA-2019-0065

Source
https://advisories.mageia.org/MGASA-2019-0065.html
Import Source
https://advisories.mageia.org/MGASA-2019-0065.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2019-0065
Related
Published
2019-02-13T11:08:25Z
Modified
2019-02-13T10:36:47Z
Summary
Updated python-marshmallow packages fix security vulnerability
Details

In the marshmallow library before 2.15.1 for Python, the schema "only" option treats an empty list as implying no "only" option, which allows a request that was intended to expose no fields to instead expose all fields (if the schema is being filtered dynamically using the "only" option, and there is a user role that produces an empty value for "only") (CVE-2018-17175).

References
Credits

Affected packages

Mageia:6 / python-marshmallow

Package

Name
python-marshmallow
Purl
pkg:rpm/mageia/python-marshmallow?arch=source&distro=mageia-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.2.1-0.5.gitea1def9.mga6

Ecosystem specific

{
    "section": "core"
}