Back to search
CVE-2019-17626
Published: Oct 16, 2019
Modified: Aug 5, 2024
PUBLISHED
Description
ReportLab through 3.5.26 allows remote code execution because of toColor(eval(arg)) in colors.py, as demonstrated by a crafted XML document with '<span color="' followed by arbitrary Python code.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
RHSA-2020:0197
vendor-advisory
RHSA-2020:0195
vendor-advisory
FEDORA-2020-d2fb999600
vendor-advisory
RHSA-2020:0230
vendor-advisory
RHSA-2020:0201
vendor-advisory
FEDORA-2020-f3e0ba2f79
vendor-advisory
openSUSE-SU-2020:0160
vendor-advisory
USN-4273-1
vendor-advisory
DSA-4663
vendor-advisory
GLSA-202007-35
vendor-advisory
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now