CVE-2011-4212
Published Oct 30, 2011
Last updated 7 years ago
Overview
- Description
- The sandbox environment in the Google App Engine Python SDK before 1.5.4 does not properly prevent os.popen calls, which allows local users to bypass intended access restrictions and execute arbitrary commands via a dev_appserver.RestrictedPathFunction._original_os reference within the code parameter to _ah/admin/interactive/execute, a different vulnerability than CVE-2011-1364.
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 7.2
- Impact score
- 10
- Exploitability score
- 3.9
- Vector string
- AV:L/AC:L/Au:N/C:C/I:C/A:C
Weaknesses
- nvd@nist.gov
- CWE-264
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:google:app_engine_python_sdk:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B180320A-31A2-4944-9237-8BA7420F607F", "versionEndIncluding": "1.5.3" }, { "criteria": "cpe:2.3:a:google:app_engine_python_sdk:1.0.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "418F092D-7DCC-4CF6-BE21-90A9E635DB29" }, { "criteria": "cpe:2.3:a:google:app_engine_python_sdk:1.0.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A802984F-7EB3-426A-B829-DE77BD54D0A7" }, { "criteria": "cpe:2.3:a:google:app_engine_python_sdk:1.1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F29B1A84-A9C9-424D-9CAE-82D8D81388EC" }, { "criteria": "cpe:2.3:a:google:app_engine_python_sdk:1.1.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A5E098ED-71C0-45BE-8607-7FCE6604155F" }, { "criteria": "cpe:2.3:a:google:app_engine_python_sdk:1.1.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4EB6A1B5-9884-4C87-A568-015F6471E80F" }, { "criteria": "cpe:2.3:a:google:app_engine_python_sdk:1.1.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B6488791-DB99-474A-AE2E-9EC5B7EED80A" }, { "criteria": "cpe:2.3:a:google:app_engine_python_sdk:1.1.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "08C5B802-51C1-4544-8DBF-E2ACF5F23981" }, { "criteria": "cpe:2.3:a:google:app_engine_python_sdk:1.1.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F5F9EB0C-D15B-4C8A-B2D1-899738AB587A" }, { "criteria": "cpe:2.3:a:google:app_engine_python_sdk:1.1.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9B8002EF-0B6E-4B06-814F-BD0FB259EE2B" }, { "criteria": "cpe:2.3:a:google:app_engine_python_sdk:1.1.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B7DD00F8-C815-4144-A230-8024C5337ECB" }, { "criteria": "cpe:2.3:a:google:app_engine_python_sdk:1.1.8:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DB94D124-3EB3-4060-A0F4-710A5EA881E7" }, { "criteria": "cpe:2.3:a:google:app_engine_python_sdk:1.1.9:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A76BC88A-C6AC-4A26-9D01-EDCB95455B5E" }, { "criteria": "cpe:2.3:a:google:app_engine_python_sdk:1.2.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "94A92AB1-CBF6-4DD1-9CF5-83043828A6C3" }, { "criteria": "cpe:2.3:a:google:app_engine_python_sdk:1.2.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0D203CA1-F53B-4D34-80D8-D86C180D0328" }, { "criteria": "cpe:2.3:a:google:app_engine_python_sdk:1.2.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A963A0BF-C8F2-49EA-BBAC-B029B8E093FA" }, { "criteria": "cpe:2.3:a:google:app_engine_python_sdk:1.2.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9D7B090E-F65F-4FC9-88FE-44A928CFD9DA" }, { "criteria": "cpe:2.3:a:google:app_engine_python_sdk:1.2.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2BF95B31-ED3B-4D51-82E4-9EA666D9D2E8" }, { "criteria": "cpe:2.3:a:google:app_engine_python_sdk:1.2.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "88354A89-1CFD-4758-8AD0-85443E251B9D" }, { "criteria": "cpe:2.3:a:google:app_engine_python_sdk:1.2.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9C7D8D57-E599-476C-BF75-2D0905E29FCE" }, { "criteria": "cpe:2.3:a:google:app_engine_python_sdk:1.2.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EA34B527-47AE-4187-B50A-BF6AC6CFE913" }, { "criteria": "cpe:2.3:a:google:app_engine_python_sdk:1.3.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "662EF41D-0DBE-466C-87F7-CA126099A737" }, { "criteria": "cpe:2.3:a:google:app_engine_python_sdk:1.3.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D5DA449B-81EF-4746-A626-E545B2B21B87" }, { "criteria": "cpe:2.3:a:google:app_engine_python_sdk:1.3.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2E6F72E0-D32A-4995-8C5A-3B7E71908DCE" }, { "criteria": "cpe:2.3:a:google:app_engine_python_sdk:1.3.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D48D7C01-07EA-4628-A975-E418705F8DD7" }, { "criteria": "cpe:2.3:a:google:app_engine_python_sdk:1.3.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4CC602DA-5413-415F-B388-C48F35511124" }, { "criteria": "cpe:2.3:a:google:app_engine_python_sdk:1.3.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2526A4F7-777B-4186-B882-C8133DBE6F15" }, { "criteria": "cpe:2.3:a:google:app_engine_python_sdk:1.3.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "427C84D8-3120-4782-AB6F-5125419313A4" }, { "criteria": "cpe:2.3:a:google:app_engine_python_sdk:1.3.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B92FB779-4C11-4DE1-901D-B86AACDD8657" }, { "criteria": "cpe:2.3:a:google:app_engine_python_sdk:1.3.8:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "336FF655-214F-49DA-AE27-C8DEA07074E9" }, { "criteria": "cpe:2.3:a:google:app_engine_python_sdk:1.4.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A4985C56-1E3C-4AC5-AE1C-609D46DF2266" }, { "criteria": "cpe:2.3:a:google:app_engine_python_sdk:1.4.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F27B63FC-B939-44AA-8CB5-8FD48CD78F00" }, { "criteria": "cpe:2.3:a:google:app_engine_python_sdk:1.4.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "55284E5B-F681-4691-98C7-5BC7259A7417" }, { "criteria": "cpe:2.3:a:google:app_engine_python_sdk:1.4.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7845EF6F-6E92-4200-AF9C-F0F738DDF4E6" }, { "criteria": "cpe:2.3:a:google:app_engine_python_sdk:1.5.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9856F64E-AF14-40C8-BC3D-E63627BF00C9" }, { "criteria": "cpe:2.3:a:google:app_engine_python_sdk:1.5.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A85D7A70-C071-4A00-8E1E-DB0DE933494E" }, { "criteria": "cpe:2.3:a:google:app_engine_python_sdk:1.5.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CA99DEEB-515E-4C19-B56A-11F5E7095306" } ], "operator": "OR" } ] } ]