Multiple sandbox escapes in asteval python sandboxing module – Full Disclosure

Posted by areca-palm via Fulldisclosure on Mar 11
[CVE pending]
Sandboxing Python is notoriously difficult, the Python module “asteval” is no exception. Add to this the fact that a
large set of numpy functions are exposed within the sandbox by default.
Versions <=1.06 are vulnerable.
This vuln has been disclosed to the maintainer, who closed the security advisory and has since pushed his own fix to
master. A CVE is still pending. Publishing the vulnerability through this list…
– Read More – Full Disclosure