Vulnerability Description
An issue was discovered in SageMath Sage Cell Server through 2019-10-05. Python Code Injection can occur in the context of an internet facing web application. Malicious actors can execute arbitrary commands on the underlying operating system, as demonstrated by an __import__('os').popen('whoami').read() line. NOTE: the vendor's position is that the product is "vulnerable by design" and the current behavior will be retained
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sagemath | Sagemathcell | All versions |
Related Weaknesses (CWE)
References
- https://gist.github.com/barrett092/0380a1c34c014e29b827d1f408381525ExploitThird Party Advisory
- https://github.com/sagemath/sagecell/commits/masterPatch
- https://sethsec.blogspot.com/2016/11/exploiting-python-code-injection-in-web.htmExploitThird Party Advisory
- https://gist.github.com/barrett092/0380a1c34c014e29b827d1f408381525ExploitThird Party Advisory
- https://github.com/sagemath/sagecell/commits/masterPatch
- https://sethsec.blogspot.com/2016/11/exploiting-python-code-injection-in-web.htmExploitThird Party Advisory
FAQ
What is CVE-2019-17526?
CVE-2019-17526 is a vulnerability with a CVSS score of 9.8 (CRITICAL). An issue was discovered in SageMath Sage Cell Server through 2019-10-05. Python Code Injection can occur in the context of an internet facing web application. Malicious actors can execute arbitrary co...
How severe is CVE-2019-17526?
CVE-2019-17526 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2019-17526?
Check the references section above for vendor advisories and patch information. Affected products include: Sagemath Sagemathcell.