Open
Description
New Issue Checklist
- I have read the Contribution GuidelinesI searched for existing GitHub issues
Issue Description
Possibility of arbitrary code execution in tensorlayer
.
Possibility of arbitrary code execution in tensorlayer
.
Activity
gurshafriri commentedon Feb 10, 2021
@zsdonghao @Laicheng0830 Did you have any chance to look at it?
If it is a valid vulnerability in the context of tensorlayer we (at Snyk would like to add it to our vulnerability db
d3m0n-r00t commentedon Feb 18, 2021
@zsdonghao Any comments on this?????
Laicheng0830 commentedon Feb 18, 2021
@d3m0n-r00t This is a potential security hole, you can fix it with Pull requests.
d3m0n-r00t commentedon Feb 19, 2021
@Laicheng0830
I have created a fix with huntr. Please find the fix here (418sec#1).
JamieSlome commentedon Feb 19, 2021
Attaching the original disclosure for reference:
418sec/huntr#1791 and https://www.huntr.dev/bounties/1-pip-tensorlayer/