Arbitrary Code Execution Affecting tqdm package, versions [,4.11.2)
Threat Intelligence
EPSS
0.04% (6th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-PYTHON-TQDM-40369
- published 25 Dec 2016
- disclosed 25 Dec 2016
- credit Jakub Wilk
Introduced: 25 Dec 2016
CVE-2016-10075 Open this link in a new tabOverview
tqdm
is a Fast, Extensible Progress Meter.
Affected versions of this package are vulnerable to Arbitrary Code Execution due to using git insecurely. When importing tqdm
, the tqdm._version
module will run git log -n 1 --oneline
in order to check if the user is running a pre-released version. An attacker can craft a repository with a malicious git log in the current working directory.
References
CVSS Scores
version 3.1