Sitelet https://github.com/python/cpython/issues/97612#top
Skip to content

[security] Tools/scripts/get-remote-certificate.py is vulnerable to shell code injection #97612

Description

@vstinner

The Tools/scripts/get-remote-certificate.py script is vulnerable to shell code injection. This vulnerability was reported by Caleb Shortt (@calebshortt).

@calebshortt proposed PR #96014 to fix it.

Activity

  1. vstinner commented on Sep 28, 2022

    @vstinner
    MemberAuthor

    Example:

    $ ./python Tools/scripts/get-remote-certificate.py 'localhost"||echo 1 > /tmp/marker #:80'
    (...)
    
    $ cat /tmp/marker 
    1
    
  2. changed the title [-][security][CVE-2022-37460] Tools/scripts/get-remote-certificate.py is vulnerable to shell code injection[/-] [+][security] Tools/scripts/get-remote-certificate.py is vulnerable to shell code injection[/+] on Sep 28, 2022
  3. vstinner commented on Sep 28, 2022

    @vstinner
    MemberAuthor
  4. added a commit that references this issue on Sep 28, 2022
  5. added 6 commits that reference this issue on Sep 28, 2022
  6. vstinner commented on Sep 29, 2022

    @vstinner
    MemberAuthor

    I created https://discuss.python.org/t/remove-outdated-tools-scripts-scripts/19571 discussion to propose removing outdated example scripts.

  7. added 3 commits that reference this issue on Oct 4, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    type-bugAn unexpected behavior, bug, or errortype-securityA security issue

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions