io/mongo/parser.py in Eve (aka pyeve) before 0.7.5 allows remote attackers to execute arbitrary code via Code Injection in the where parameter.
References
Link | Resource |
---|---|
https://github.com/pyeve/eve/issues/1101 | Third Party Advisory |
https://github.com/pyeve/eve/commit/f8f7019ffdf9b4e05faf95e1f04e204aa4c91f98 | Patch Third Party Advisory |
Configurations
Information
Published : 2018-03-14 05:29
Updated : 2018-04-10 11:46
NVD link : CVE-2018-8097
Mitre link : CVE-2018-8097
JSON object : View
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')
Products Affected
python-eve
- eve