VDB
Sign up
—

PYSEC-2018-8

Quick fix

PYSEC-2018-8 — eve: upgrade to the fixed version with the command below.

pip install --upgrade 'eve>=f8f7019ffdf9b4e05faf95e1f04e204aa4c91f98'

Details

io/mongo/parser.py in Eve (aka pyeve) before 0.7.5 allows remote attackers to execute arbitrary code via Code Injection in the where parameter.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/eve
Introduced in: 0Fixed in: f8f7019ffdf9b4e05faf95e1f04e204aa4c91f98
Fixpip install --upgrade 'eve>=f8f7019ffdf9b4e05faf95e1f04e204aa4c91f98'

References