VDB
CVE-2023-49297
CVE-2023-49297
PUBLISHED
CVSS 3.299999952316284 LOW
PyDrive2's unsafe YAML deserialization in LoadSettingsFile allows arbitrary code execution
EPSS 0.51% · 40.8th percentile
Risk Scores
CVSS 3.1
3.299999952316284
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
EPSS Score
0.51%
40.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| iterative | pydrive2 | 1.17.0, 1.17.0, 0 |
| iterative | PyDrive2 | = 1.17.0, < 1.16.2, * |
| PyPI | PyDrive2 | 1.17.0, 0, 1.17.0 |
Timeline
- Dec 5, 2023 CVE Published
- Dec 6, 2023 EPSS Score
- Dec 24, 2023 PoC Published
- Jan 5, 2024 EPSS Score
- Feb 3, 2024 EPSS Score
- Mar 4, 2024 EPSS Score
- Apr 2, 2024 EPSS Score
- May 2, 2024 EPSS Score
- May 31, 2024 EPSS Score
- Jun 30, 2024 EPSS Score
- Jul 29, 2024 EPSS Score
- Aug 28, 2024 EPSS Score
References
- https://github.com/iterative/PyDrive2/security/advisories/GHSA-v5f6-hjmf-9mc5 url
- https://github.com/iterative/PyDrive2/commit/c57355dc2033ad90b7050d681b2c3ba548ff0004 url
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/K34YWTDKBAYWZPOAKBYDM72WIFL5CAYW/ url
- https://nvd.nist.gov/vuln/detail/CVE-2023-49297 advisory
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CYR5SJKOFSSXFV3E3D2SLXBUBA5WMJJG url
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CYR5SJKOFSSXFV3E3D2SLXBUBA5WMJJG/ url
- https://github.com/iterative/PyDrive2 package
- https://github.com/pypa/advisory-database/tree/main/vulns/pydrive2/PYSEC-2023-291.yaml url
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/K34YWTDKBAYWZPOAKBYDM72WIFL5CAYW url