VAITP Dataset

Dataset Statistics
Search for CVE
#
CVE
Vulnerability
ODC
Category
Subcategory
Accessibility Scope
Details
Total vulnerabilities in the dataset (not showing ignored and non-python related vulnerabilties): 1787
608
Remote code execution via unsafe pickle usage in S3QL versions 1.18.1 and earlier

S3QL 1.18.1 and earlier uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via a crafted serialized object in (1) common.py or (2) local.py in backends/.

Timing/Serialization
Input Validation and Sanitization
Insecure Parsing or Deserialization
Remote
607
Static code injection in DeStar 0.2.2-5 lets authenticated users add admins and inject Python code via a crafted "pin" parameter

Static code injection vulnerability in user/settings/ in DeStar 0.2.2-5 allows remote authenticated users to add arbitrary administrators and inject arbitrary Python code into destar_cfg.py via a crafted pin parameter.

Function
Input Validation and Sanitization
Command Injection
Remote
606
Blender 2.36's bvh_import.py allows arbitrary Python code execution via a .bvh file's hierarchy element

Eval injection vulnerability in bvh_import.py in Blender 2.36 allows attackers to execute arbitrary Python code via a hierarchy element in a .bvh file, which is supplied to an eval function call.

Function
Input Validation and Sanitization
Insecure Parsing or Deserialization
Remote
605
XWiki Platform 7.2-11.10.2: Registered users can run Python/Groovy scripts in personal dashboards. Fixed in 11.3.7, 11.10.3, 12.0

In XWiki Platform 7.2 through 11.10.2, registered users without scripting/programming permissions are able to execute python/groovy scripts while editing personal dashboards. This has been fixed 11.3.7 , 11.10.3 and 12.0.

Function
Input Validation and Sanitization
Insecure Direct Object References (IDOR)
Remote
604
OpenStack config file leaks secret key

The file /etc/openstack-dashboard/local_settings within Red Hat OpenStack Platform 2.0 and RHOS Essex Release (python-django-horizon package before 2012.1.1) is world readable and exposes the secret key value.

Function
Design Defects
Security Misconfigurations
Local
603
Directory traversal vulnerability in Bitty 0.2.10 via URL path in GET requests

Bitty is a development web server tool that functions similar to `python -m SimpleHTTPServer`. Version 0.2.10 has a directory traversal vulnerability that is exploitable via the URL path in GET requests.

Function
Input Validation and Sanitization
Path Traversal
Remote
602
Python console in Electrum v2.9.4 - v3.0.5 allows arbitrary code execution, risking Bitcoin theft

The Python console in Electrum through 2.9.4 and 3.x through 3.0.5 supports arbitrary Python code without considering (1) social-engineering attacks in which a user pastes code that they do not understand and (2) code pasted by a physically proximate attacker at an unattended workstation, which makes it easier for attackers to steal Bitcoin via hook code that runs at a later time when the wallet password has been entered, a different vulnerability than CVE-2018-1000022.

Function
Input Validation and Sanitization
Insecure Parsing or Deserialization
Local
601
Unauthenticated attackers exploit Red Hat Ceph Storage 2 and 3's ceph-isci-cli vulnerability for remote root-level access via enabled debug shell in python-werkzeug

It was found that ceph-isci-cli package as shipped by Red Hat Ceph Storage 2 and 3 is using python-werkzeug in debug shell mode. This is done by setting debug=True in file /usr/bin/rbd-target-api provided by ceph-isci-cli package. This allows unauthenticated attackers to access this debug shell and escalate privileges. Once an attacker has successfully connected to this debug shell they will be able to execute arbitrary commands remotely. These commands will run with the same privileges as of user executing the application which is using python-werkzeug with debug shell mode enabled. In - Red Hat Ceph Storage 2 and 3, ceph-isci-cli package runs python-werkzeug library with root level permissions.

Function
Authentication, Authorization, and Session Management
Privilege Escalation
Remote
600
Ignition < 7.9.20 and 8.x < 8.1.17, RCE via ScriptInvoke

An issue was discovered in Inductive Automation Ignition before 7.9.20 and 8.x before 8.1.17. The ScriptInvoke function allows remote attackers to execute arbitrary code by supplying a Python script.

Function
Input Validation and Sanitization
Command Injection
Remote
599
Plone 4.x through 4.3.11 and 5.x through 5.0.6 have remote code execution due to a Python string format method issue

Plone 4.x through 4.3.11 and 5.x through 5.0.6 allow remote attackers to bypass a sandbox protection mechanism and obtain sensitive information by leveraging the Python string format method.

Function
Information Leakage
Information Disclosure
Remote
Introducing the "VAITP dataset": a specialized repository of Python vulnerabilities and patches, meticulously compiled for the use of the security research community. As Python's prominence grows, understanding and addressing potential security vulnerabilities become crucial. Crafted by and for the cybersecurity community, this dataset offers a valuable resource for researchers, analysts, and developers to analyze and mitigate the security risks associated with Python. Through the comprehensive exploration of vulnerabilities and corresponding patches, the VAITP dataset fosters a safer and more resilient Python ecosystem, encouraging collaborative advancements in programming security.

The supreme art of war is to subdue the enemy without fighting.

Sun Tzu – “The Art of War”

:: Shaping the future through research and ingenuity ::