—
PYSEC-2019-116
Quick fix
PYSEC-2019-116 — rediswrapper: upgrade to the fixed version with the command below.
pip install --upgrade 'rediswrapper>=0.3.0'Details
Uncontrolled deserialization of a pickled object in models.py in Frost Ming rediswrapper (aka Redis Wrapper) before 0.3.0 allows attackers to execute arbitrary scripts.
Are you affected?
Enter the version of the package you're using.