core.py in Mitogen before 0.2.8 has a typo that drops the unidirectional-routing protection mechanism in the case of a child that is initiated by another child. The Ansible extension is unaffected. NOTE: the vendor disputes this issue because it is exploitable only in conjunction with hypothetical other factors, i.e., an affected use case within a library caller, and a bug in the message receiver policy code that led to reliance on this extra protection mechanism
Software security is not security software. Here we're concerned with topics like authentication, access control, confidentiality, cryptography, and privilege management.
Link | Tags |
---|---|
https://github.com/dw/mitogen/commit/5924af1566763e48c42028399ea0cd95c457b3dc | third party advisory patch |
https://mitogen.networkgenomics.com/changelog.html#v0-2-8-2019-08-18 | release notes |