File size: 635 Bytes
58fe8fa
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
---
name: deserialization-python
domain: web
triggers:
  languages: [python]
severity_focus: [P1, P2, P3]
---

# deserialization-python

Python deser: pickle (any unpickle of untrusted data is RCE), PyYAML yaml.load() pre-5.1, marshal, jsonpickle, dill. Detection: any *.load(...) on user-controlled bytes.

## Detection checklist
- enumerate exposure
- match canonical sinks
- confirm reproducibility
- map to CWE / OWASP / CVSS

## Exploitation primitives
- reproduce in lab
- minimise the PoC
- assess blast radius

## Reporting fingerprint
- include affected version range
- include suggested fix snippet
- include CVSS 3.1 vector