Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

[CVE-2023-39631] Beyond the Bands: Exploiting TiTiler’s Expression Parser for Remote Code Execution

xbow.com | vulnerability | Critical | CVE-2023-39631 | #rce | #vulnerability-research | #python | #code-execution | #titiler | #expression-parser

Summary

A methodical study of TiTiler's expression parser that ends in arbitrary Python code execution on the server, with a bonus arbitrary file read saved for a follow-up post.
CVSS
9.8
Published
Collected

original ↗

Related coverage

back