漏洞描述
In RPyC 4.1.x through 4.1.1, a remote attacker can dynamically modify object attributes to construct a remote procedure call that executes code for an RPyC service with default configuration settings.
影响产品
暂无结构化产品信息。
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
lists.opensuse.orghttp://lists.opensuse.org/opensuse-security-announce/2020-05/msg00046.html↗github.comhttps://github.com/tomerfiliba/rpyc↗lists.opensuse.orghttp://lists.opensuse.org/opensuse-security-announce/2020-06/msg00004.html↗rpyc.readthedocs.iohttps://rpyc.readthedocs.io/en/latest/docs/security.html↗