Fabfile is a Python-based deployment and systems administration automation tool; its vulnerability profile centers on the core Fabric library and reflects risks inherent to file-system operations and privilege escalation in automation contexts. The durable signal is a recurring weakness in improper link resolution before file access, a mechanism by which symlink-following attacks can be mounted against automation scripts running with elevated privileges. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Fabfile over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2011-2185MEDIUM Fabric before 1.1.0 allows local users to overwrite arbitrary files via a symlink attack on (1) a /tmp/fab.*.tar file or (2) certain other files in the top level of /tmp/. | Jul 27, 2011 | 4.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Fabfile.
Media articles that mention a CVE ID that affects a product developed by Fabfile — matched by CVE ID, not by vendor name.