CVE-2018-17175
Published Sep 18, 2018In the marshmallow library before 2.15.1 and 3.x before 3.0.0b9 for Python, the schema "only" option treats an empty list as implying no "only" option, which allows a request that…
Vendor archive
1 CVEs tagged to vendor marshmallow_project — 0 Critical, 0 High, 1 Medium, 0 Low, 0 Unrated.
In the marshmallow library before 2.15.1 and 3.x before 3.0.0b9 for Python, the schema "only" option treats an empty list as implying no "only" option, which allows a request that…