Safety是一款基于Python的用于检查程序安全性的软件包。
Safety 1.8.6及之前版本中存在安全漏洞。攻击者可借助特制的软件包利用该漏洞绕过安全检查。
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://github.com/pyupio/safety/security/advisories/GHSA-7q25-qrjw-6fg2
来源:CONFIRM
链接:https://github.com/akoumjian/python-safety-vuln
来源:CONFIRM
链接:https://pyup.io/posts/patched-vulnerability/
来源:CONFIRM
链接:https://github.com/pyupio/safety/security/advisories/GHSA-7q25-qrjw-6fg2
来源:nvd.nist.gov
链接:https://nvd.nist.gov/vuln/detail/CVE-2020-5252