CVE-2021-47952
Jsonpickle python jsonpickle, Red Hat Ansible Automation Platform 2 취약점
python jsonpickle 2.0.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary Python commands by deserializing malicious JSON payloads containing py/repr objects. Attackers can craft JSON strings with py/repr directives that invoke the eval function during deserialization to execute arbitrary code.
- 대응 우선순위
- 점검
- CVSS
- 9.3
- EPSS
- 0.70% 백분위 49.5% · 2026.08.02 기준
- CISA KEV
- 미등록
- 조치 기한
- -
- 공개일
- 2026.05.17