VDB
Sign up
—

PYSEC-2023-177

Quick fix

PYSEC-2023-177 — gevent: upgrade to the fixed version with the command below.

pip install --upgrade 'gevent>=2f53c851eaf926767fbac62385615efd4886221c'

Details

An issue in Gevent before version 23.9.0 allows a remote attacker to escalate privileges via a crafted script to the WSGIServer component.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/gevent
Introduced in: 0Fixed in: 2f53c851eaf926767fbac62385615efd4886221c
Fixpip install --upgrade 'gevent>=2f53c851eaf926767fbac62385615efd4886221c'

References