vendor:
rpc.py
by:
Elias Hohl
9.8
CVSS
CRITICAL
Remote Code Execution (RCE)
502
CWE
Product Name: rpc.py
Affected Version From: v0.4.2
Affected Version To: v0.6.0
Patch Exists: YES
Related CWE: CVE-2022-35411
CPE: a:abersheeran:rpc.py
Platforms Tested: Debian 11, Ubuntu 20.04
2022
rpc.py 0.6.0 – Remote Code Execution (RCE)
A 0-day unauthenticated Remote Code Execution (RCE) vulnerability was discovered in rpc.py versions v0.4.2 - v0.6.0. An attacker can exploit this vulnerability by sending a malicious serialized payload to the vulnerable server using the pickle serializer. This payload can be used to execute arbitrary commands on the vulnerable server.
Mitigation:
Upgrade to the latest version of rpc.py, which is not vulnerable to this exploit.