CVE-2013-5093
Publication date 27 September 2013
Last updated 24 July 2024
Ubuntu priority
The renderLocalView function in render/views.py in graphite-web in Graphite 0.9.5 through 0.9.10 uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via a crafted serialized object.
Status
Package | Ubuntu Release | Status |
---|---|---|
graphite-web | ||
Notes
seth-arnold
upstream 0.9.12 includes some XSS fixes that don't (yet?) have a CVE entry; a full update might be better.