PYSEC-2020-71

See a problem?
Import Source
https://github.com/pypa/advisory-database/blob/main/vulns/openapi-python-client/PYSEC-2020-71.yaml
JSON Data
https://api.osv.dev/v1/vulns/PYSEC-2020-71
Aliases
Published
2020-08-14T17:15:00Z
Modified
2023-11-08T04:02:31.004919Z
Summary
[none]
Details

In openapi-python-client before version 0.5.3, clients generated with a maliciously crafted OpenAPI Document can generate arbitrary Python code. Subsequent execution of this malicious client is arbitrary code execution.

References

Affected packages

PyPI / openapi-python-client

Package

Name
openapi-python-client
View open source insights on deps.dev
Purl
pkg:pypi/openapi-python-client

Affected ranges

Type
GIT
Repo
https://github.com/triaxtec/openapi-python-client
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.5.3

Affected versions

0.*

0.1.0.dev0
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.3.0
0.4.0rc1
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2