3 ms·
But the author fixed it? https://github.com/delgan/loguru/commit/4b0070a4f30cbf6d5e12e6274b242b62ea11c81b https://github.com/delgan/loguru/commit/4b0070a4f30cbf
by zsims 5y ago
But the author fixed it? https://github.com/delgan/loguru/commit/4b0070a4f30cbf6d5e12e6274b242b62ea11c81b https://github.com/delgan/loguru/commit/4b0070a4f30cbf6d5e12...
Obviously there was something the library could "do better." I think the root of this issue is trying to squeeze absolutely everything into CVSS
- rcxdude 5y agoFrom what I can tell all this does is move the pickling process to the multiprocessing module, so it 'fixes the problem' by moving the call to pickle into the standard library (so automated code auditing tools or the dude complaining about the usage won't find it) and just removes some (useful) error handling in the process, as well as repeating the pickling process twice. It's entirely an effort to shut up the complaining and doesn't meaningfully change the security of the system at all (which was already fine).
- orf 5y agoThat’s not the point - the function wasn’t exploitable and the vulnerability report made no attempt to show that it was exploitable. It showed how to call it. And yet, we have a CVE.