CVE-2025-46417

7.5HIGH

The unsafe globals in Picklescan before 0.0.25 do not include ssl. Consequently, ssl.get_server_certificate can exfiltrate data via DNS after deserialization.

Опубликовано: 4/24/2025Обновлено: 10/1/2025

Описание

The unsafe globals in Picklescan before 0.0.25 do not include ssl. Consequently, ssl.get_server_certificate can exfiltrate data via DNS after deserialization.

ИИ-АнализНа базе ИИ

Затронутые продукты

mmaitre314picklescan

Ссылки