{"id":"UBUNTU-CVE-2018-17175","details":"In the marshmallow library before 2.15.1 and 3.x before 3.0.0b9 for Python, the schema \"only\" option treats an empty list as implying no \"only\" option, which allows a request that was intended to expose no fields to instead expose all fields (if the schema is being filtered dynamically using the \"only\" option, and there is a user role that produces an empty value for \"only\").","modified":"2026-04-30T09:37:45.291378Z","published":"2018-09-18T17:29:00Z","related":["USN-8225-1"],"upstream":["CVE-2018-17175"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2018-17175"},{"type":"REPORT","url":"https://github.com/marshmallow-code/marshmallow/issues/772"},{"type":"REPORT","url":"https://github.com/marshmallow-code/marshmallow/pull/777"},{"type":"REPORT","url":"https://github.com/marshmallow-code/marshmallow/pull/782"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2018-17175"},{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-8225-1"}],"affected":[{"package":{"name":"python-marshmallow","ecosystem":"Ubuntu:Pro:18.04:LTS","purl":"pkg:deb/ubuntu/python-marshmallow@3.0.0b3-1ubuntu0.1~esm1?arch=source&distro=esm-apps/bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.0.0b3-1ubuntu0.1~esm1"}]}],"versions":["3.0.0b3-1"],"ecosystem_specific":{"availability":"Available with Ubuntu Pro: https://ubuntu.com/pro","binaries":[{"binary_name":"python3-marshmallow","binary_version":"3.0.0b3-1ubuntu0.1~esm1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2018/UBUNTU-CVE-2018-17175.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"},{"type":"Ubuntu","score":"low"}]}