fabric@0.9.4 vulnerabilities

High level SSH command execution

Direct Vulnerabilities

Known vulnerabilities in the fabric package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • L
Information Exposure

fabric is a Fabric is a simple, Pythonic tool for remote execution and deployment. Fabric is vulnerable to information disclosure. When uploading templates using the upload_template() function, if the intended destination is invalid, the file ends up world-readable in the home folder.

  • M
Overwritable Files

fabric is a Fabric is a simple, Pythonic tool for remote execution and deployment. Fabric before 1.1.0 allows local users to overwrite arbitrary files via a symlink attack on (1) a /tmp/fab.tar file or (2) certain other files in the top level of /tmp/.
