{"id":"GHSA-cf3c-fffp-34qh","summary":"conference-scheduler-cli Arbitrary Code Execution","details":"In conference-scheduler-cli, a pickle.load call on imported data allows remote attackers to execute arbitrary code via a crafted .pickle file, as demonstrated by Python code that contains an os.system call.","aliases":["CVE-2018-14572","PYSEC-2018-64"],"modified":"2024-09-13T18:23:07.514669Z","published":"2018-10-29T19:05:38Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2020-06-16T21:31:12Z","nvd_published_at":null,"cwe_ids":["CWE-502","CWE-78"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2018-14572"},{"type":"WEB","url":"https://github.com/PyconUK/ConferenceScheduler-cli/issues/19"},{"type":"PACKAGE","url":"https://github.com/PyconUK/ConferenceScheduler-cli"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-cf3c-fffp-34qh"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/conference-scheduler-cli/PYSEC-2018-64.yaml"},{"type":"WEB","url":"https://joel-malwarebenchmark.github.io/blog/2020/04/25/cve-2018-14572-conference-scheduler-cli"}],"affected":[{"package":{"name":"conference-scheduler-cli","ecosystem":"PyPI","purl":"pkg:pypi/conference-scheduler-cli"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"0.10.1"}]}],"versions":["0.1.0","0.10.1","0.2.0","0.3.0","0.3.1","0.4.0","0.4.1","0.5.0","0.6.0","0.7.0","0.7.1","0.7.2","0.8.0","0.8.1","0.8.2","0.8.3","0.8.4","0.9.0","0.9.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/10/GHSA-cf3c-fffp-34qh/GHSA-cf3c-fffp-34qh.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}