CVE-2018-17175 describes a vulnerability in the marshmallow library (versions before 2.15.1 and 3.x before 3.0.0b9) for Python. This flaw allows an attacker to bypass intended field restrictions, potentially exposing all fields of a schema when an empty "only" option is dynamically applied. Rated as Medium severity (CVSS 5.3), it is a network-exploitable vulnerability with low attack complexity, leading to a potential loss of confidentiality. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.15.1CPE matchmatch criteria | cpe:2.3:a:marshmallow_project:marshmallow:*:*:*:*:*:*:*:* | ||
>= 3.0, < 3.0.0b9CPE matchmatch criteria | cpe:2.3:a:marshmallow_project:marshmallow:*:*:*:*:*:python:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.