Cheetah Path Search Order Hijacking
High severity
GitHub Reviewed
Published
May 1, 2022
to the GitHub Advisory Database
•
Updated Sep 18, 2023
Description
Published by the National Vulnerability Database
May 17, 2005
Published to the GitHub Advisory Database
May 1, 2022
Reviewed
Sep 18, 2023
Last updated
Sep 18, 2023
Cheetah 0.9.15 and 0.9.16 searches the
/tmp
directory for modules before using the paths in thePYTHONPATH
variable, which allows local users to execute arbitrary code via a malicious module in/tmp/
.References