CVE-2013-2217

Description

cache.py in Suds 0.4, when tempdir is set to None, allows local users to redirect SOAP queries and possibly have other unspecified impact via a symlink attack on a cache file with a predictable name in /tmp/suds/.

Risk Information

Base Score
6.2
MODERATE
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS Score
Exploitation Probability
0.135

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2013-2217 are fixed in Python-suds 1.0.0Windows
Vulnerabilities CVE-2013-2217 are fixed in Python-suds-py3 1.4.4.1Windows
Vulnerabilities CVE-2013-2217 are fixed in Python-suds for linux 1.0.0Linux
Vulnerabilities CVE-2013-2217 are fixed in Python-suds-py3 for linux 1.4.4.1Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234