Candidate: CVE-2020-15271 PublicDate: 2020-10-26 18:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15271 https://github.com/d0c-s4vage/lookatme/security/advisories/GHSA-c84h-w6cr-5v8q https://github.com/d0c-s4vage/lookatme/commit/72fe36b784b234548d49dae60b840c37f0eb8d84 (v2.3.0) https://github.com/d0c-s4vage/lookatme/pull/110 Description: In lookatme (python/pypi package) versions prior to 2.3.0, the package automatically loaded the built-in "terminal" and "file_loader" extensions. Users that use lookatme to render untrusted markdown may have malicious shell commands automatically run on their system. This is fixed in version 2.3.0. As a workaround, the `lookatme/contrib/terminal.py` and `lookatme/contrib/file_loader.py` files may be manually deleted. Additionally, it is always recommended to be aware of what is being rendered with lookatme. Ubuntu-Description: Notes: Mitigation: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=972988 Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H [8.8 HIGH] Patches_lookatme: upstream_lookatme: released (2.3.0-1) precise/esm_lookatme: DNE trusty_lookatme: ignored (out of standard support) trusty/esm_lookatme: DNE xenial_lookatme: DNE bionic_lookatme: DNE focal_lookatme: DNE groovy_lookatme: DNE devel_lookatme: not-affected (2.3.0-1)