CVE-2023-35932
Last modified
CVE-2023-35932 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. jcvi is a Python library to facilitate genome assembly, annotation, and comparative genomics. A configuration injection happens when user input is considered by the application in an unsanitized format and can reach the configuration file. EPSS estimates a 1.84% chance of exploitation in the next 30 days.
Description
jcvi is a Python library to facilitate genome assembly, annotation, and comparative genomics. A configuration injection happens when user input is considered by the application in an unsanitized format and can reach the configuration file. A malicious user may craft a special payload that may lead to a command injection. The impact of a configuration injection may vary. Under some conditions, it may lead to command injection if there is for instance shell code execution from the configuration file values. This vulnerability does not currently have a fix.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Jcvi Project | Jcvi | <= 1.3.5 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-35932?
How severe is CVE-2023-35932?
How do I fix CVE-2023-35932?
Are you affected by CVE-2023-35932?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
