Remote Code Execution in Custom Integration Upload in Fides
CVE-2023-41319
What is CVE-2023-41319?
The Fides privacy engineering platform contains a vulnerability that allows arbitrary code execution on the webserver's Python process due to improper sandboxing during the integration of custom Python code. This exploitation is contingent on specific configurations, notably the enabling of allow_custom_connector_functions, which sets the stage for this significant risk, primarily impacting privileged API clients. The vulnerability affects versions 2.11.0 through 2.19.0 and can lead to potential attacks on the underlying infrastructure. It is crucial for users to upgrade to version 2.19.0 or later to mitigate this risk, or, if unable to upgrade, to ensure configuration parameters for custom connectors are set appropriately to prevent exploitation.
Affected Version(s)
fides >= 2.11.0, < 2.19.0
