pandasPYSEC-2020-73
** DISPUTED ** pandas through 1.0.3 can unserialize and execute commands from an untrusted file that is passed to the read_pickle() function, if __reduce__ makes an os.system call. NOTE: third parties dispute this issue because the read_pickle() function is documented as unsafe and it is the user's
Critical9.8CVE-2020-13091 · Published May 15, 2020 · updated Nov 8, 2023
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| pandas PyPI | < 1.0.4 | 1.0.4 |
Changes since it was listed
| Date | Change |
|---|---|
| Sep 24 | Severity: Unrated to Critical |
Details and references
** DISPUTED ** pandas through 1.0.3 can unserialize and execute commands from an untrusted file that is passed to the read_pickle() function, if __reduce__ makes an os.system call. NOTE: third parties dispute this issue because the read_pickle() function is documented as unsafe and it is the user's responsibility to use the function in a secure manner.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity from
- NVD
- Also known as
- CVE-2020-13091