Race Condition Affecting execnet package, versions [,1.0.6)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-PYTHON-EXECNET-6840361
- published 14 May 2024
- disclosed 1 May 2024
- credit Unknown
How to fix?
Upgrade execnet
to version 1.0.6 or higher.
Overview
execnet is an execnet: rapid multi-Python deployment
Affected versions of this package are vulnerable to Race Condition when multiple threads simultaneously transmit data over channels, which can lead to crashes in the serializer and process.
References
CVSS Scores
version 3.1