CVE-2014-3539 describes a critical remote code execution vulnerability in the Rope library, specifically within the base/oi/doa.py component, affecting CPython (Python). This flaw stems from an unsafe call to pickle.load, allowing unauthenticated attackers to execute arbitrary code with no user interaction required. With a CVSS score of 9.8 (Critical), the vulnerability carries the highest possible impact on confidentiality, integrity, and availability. While there is no evidence of active exploitation, nor are there public exploits in Metasploit or ExploitDB, the vulnerability has garnered significant community discussion, indicating awareness among security researchers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.11.0CPE matchmatch criteria | cpe:2.3:a:rope_project:rope:*:*:*:*:*:python:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.