6.8
CVSSv2

CVE-2013-5942

Published: 27/09/2013 Updated: 07/10/2013
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Graphite 0.9.5 up to and including 0.9.10 uses the pickle Python module unsafely, which allows remote malicious users to execute arbitrary code via a crafted serialized object, related to (1) remote_storage.py, (2) storage.py, (3) render/datalib.py, and (4) whitelist/views.py, a different vulnerability than CVE-2013-5093.

Vulnerable Product Search on Vulmon Subscribe to Product

graphite project graphite 0.9.5

graphite project graphite 0.9.6

graphite project graphite 0.9.7

graphite project graphite 0.9.8

graphite project graphite 0.9.10

graphite project graphite 0.9.9