Candidate: CVE-2019-16328 PublicDate: 2019-10-03 20:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-16328 Description: In RPyC 4.1.x through 4.1.1, a remote attacker can dynamically modify object attributes to construct a remote procedure call that executes code for an RPyC service with default configuration settings. Ubuntu-Description: Notes: Mitigation: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N [7.5 HIGH] Patches_rpyc: upstream_rpyc: released (4.1.2) precise/esm_rpyc: DNE trusty_rpyc: ignored (out of standard support) trusty/esm_rpyc: DNE xenial_rpyc: DNE bionic_rpyc: not-affected (3.4.4-1) focal_rpyc: DNE groovy_rpyc: DNE devel_rpyc: DNE