GHSA-vccg-f4gp-45x9
Eval Injection in fastbots
Quick fix
GHSA-vccg-f4gp-45x9 — fastbots: upgrade to the fixed version with the command below.
pip install --upgrade 'fastbots>=0.1.5'Details
### Impact An attacker could modify the locators.ini locator file with python code that without proper validation it's executed and it could lead to rce. The vulnerability is in the function def __locator__(self, locator_name: str) in page.py. The vulnerable code that load and execute directly from the file without validation it's: ```python return eval(self._bot.locator(self._page_name, locator_name)) ```
### Patches In order to mitigate this issue it's important to upgrade to fastbots version 0.1.5 or above.
### References [Merge that fix also this issue](https://github.com/ubertidavide/fastbots/pull/3#issue-2003080806)
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/ubertidavide/fastbots/security/advisories/GHSA-vccg-f4gp-45x9[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2023-48699[ADVISORY]
- https://github.com/ubertidavide/fastbots/pull/3#issue-2003080806[WEB]
- https://github.com/ubertidavide/fastbots/commit/73eb03bd75365e112b39877e26ef52853f5e9f57[WEB]
- https://github.com/ubertidavide/fastbots[PACKAGE]