peter bassill · operator
$ cve CVE-2022-35411 JSON

CVE-2022-35411 EXPLOIT

9.8
CRITICAL · CVSS 3.1 · EPSS 45.7% (pctl 99)

Patch early

A public exploit exists.

Description

rpc.py through 0.6.0 allows Remote Code Execution because an unpickle occurs when the "serializer: pickle" HTTP header is sent. In other words, although JSON (not Pickle) is the default data format, an unauthenticated client can cause the data to be processed with unpickle.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS45.72% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-522
On CISA KEVno
Public exploityes
Published2022-07-08
Last modified2026-06-17

Affected (1)

VendorProduct
rpc.py projectrpc.py

Public exploits

SourceTitleDate
exploit-dbrpc.py 0.6.0 - Remote Code Execution (RCE)2022-07-29

References

→ the Explorer  ·  watch your stack  ·  NVD