—
PYSEC-2009-5
Quick fix
PYSEC-2009-5 — formencode: upgrade to the fixed version with the command below.
pip install --upgrade 'formencode>=1.0.1'Details
schema.py in FormEncode for Python (python-formencode) 1.0 does not apply the chained_validators feature, which allows attackers to bypass intended access restrictions via unknown vectors.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00607.html[WEB]
- http://secunia.com/advisories/31163[ADVISORY]
- http://sourceforge.net/tracker/download.php?group_id=91231&atid=596416&file_id=271779&aid=1925164[WEB]
- http://osvdb.org/47082[WEB]
- http://sourceforge.net/tracker/index.php?func=detail&aid=1925164&group_id=91231&atid=596416[WEB]
- http://secunia.com/advisories/31081[ADVISORY]
- http://www.securityfocus.com/bid/30282[WEB]
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43878[WEB]
- https://github.com/advisories/GHSA-9jp4-68vc-r8wq[ADVISORY]