Vulnerabilities > CVE-2020-13091 - Deserialization of Untrusted Data vulnerability in Numfocus Pandas

047910
CVSS 9.8 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
numfocus
CWE-502
critical

Summary

pandas through 1.0.3 can unserialize and execute commands from an untrusted file that is passed to the read_pickle() function, if __reduce__ makes an os.system call. NOTE: third parties dispute this issue because the read_pickle() function is documented as unsafe and it is the user's responsibility to use the function in a secure manner

Vulnerable Configurations

Part Description Count
Application
Numfocus
94

Common Weakness Enumeration (CWE)