Undirectional routing wasn't respected in some cases in Mitogen
Critical severity
GitHub Reviewed
Published
Aug 19, 2019
to the GitHub Advisory Database
•
Updated Sep 25, 2024
Withdrawn
This advisory was withdrawn on Aug 20, 2019
Description
Published by the National Vulnerability Database
Aug 18, 2019
Reviewed
Aug 19, 2019
Published to the GitHub Advisory Database
Aug 19, 2019
Withdrawn
Aug 20, 2019
Last updated
Sep 25, 2024
core.py in Mitogen before 0.2.8 has a typo that drops the unidirectional-routing protection mechanism in the case of a child that is initiated by another child. The Ansible extension is unaffected. NOTE: the vendor disputes this issue because it is exploitable only in conjunction with hypothetical other factors, i.e., an affected use case within a library caller, and a bug in the message receiver policy code that led to reliance on this extra protection mechanism.
References