Vulnerability Description
In RPyC 4.1.x through 4.1.1, a remote attacker can dynamically modify object attributes to construct a remote procedure call that executes code for an RPyC service with default configuration settings.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Rpyc Project | Rpyc | >= 4.1.0, <= 4.1.1 |
Related Weaknesses (CWE)
References
- http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00046.htmlBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00004.htmlBroken Link
- https://github.com/tomerfiliba/rpycProductThird Party Advisory
- https://rpyc.readthedocs.io/en/latest/docs/security.htmlExploitVendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00046.htmlBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00004.htmlBroken Link
- https://github.com/tomerfiliba/rpycProductThird Party Advisory
- https://rpyc.readthedocs.io/en/latest/docs/security.htmlExploitVendor Advisory
FAQ
What is CVE-2019-16328?
CVE-2019-16328 is a vulnerability with a CVSS score of 7.5 (HIGH). In RPyC 4.1.x through 4.1.1, a remote attacker can dynamically modify object attributes to construct a remote procedure call that executes code for an RPyC service with default configuration settings.
How severe is CVE-2019-16328?
CVE-2019-16328 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-16328?
Check the references section above for vendor advisories and patch information. Affected products include: Rpyc Project Rpyc.