Source: python-marshmallow
Version: 3.0.0b3-1
Severity: important
Tags: security upstream
Forwarded: https://github.com/marshmallow-code/marshmallow/issues/772

Hi,

The following vulnerability was published for python-marshmallow.

CVE-2018-17175[0]:
| In the marshmallow library before 2.15.1 and 3.x before 3.0.0b9 for
| Python, the schema "only" option treats an empty list as implying no
| "only" option, which allows a request that was intended to expose no
| fields to instead expose all fields (if the schema is being filtered
| dynamically using the "only" option, and there is a user role that
| produces an empty value for "only").

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2018-17175
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-17175
[1] https://github.com/marshmallow-code/marshmallow/issues/772
[2] https://github.com/marshmallow-code/marshmallow/pull/777
[3] https://github.com/marshmallow-code/marshmallow/pull/782

Regards,
Salvatore

Reply via email to