High severity7.5NVD Advisory· Published Oct 3, 2019· Updated Jun 17, 2026
CVE-2019-16328
CVE-2019-16328
Description
In RPyC 4.1.x through 4.1.1, a remote attacker can dynamically modify object attributes to construct a remote procedure call that executes code for an RPyC service with default configuration settings.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
rpycPyPI | >= 4.1.0, < 4.1.1 | 4.1.1 |
Affected products
8- RPyC/RPyCdescription
- ghsa-coords6 versionspkg:pypi/rpycpkg:rpm/opensuse/python-rpyc-test&distro=openSUSE%20Leap%2015.1pkg:rpm/suse/python-rpyc&distro=SUSE%20Package%20Hub%2015%20SP1pkg:rpm/suse/python-rpyc-test&distro=SUSE%20Package%20Hub%2015%20SP1pkg:rpm/opensuse/python-rpyc&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/python-rpyc&distro=openSUSE%20Leap%2015.1
>= 4.1.0, < 4.1.1+ 5 more
- (no CPE)range: >= 4.1.0, < 4.1.1
- (no CPE)range: < 4.1.5-lp151.3.3.1
- (no CPE)range: < 4.1.5-bp151.2.3.1
- (no CPE)range: < 4.1.5-bp151.2.3.1
- (no CPE)range: < 6.0.0-1.2
- (no CPE)range: < 4.1.5-lp151.3.3.1
Patches
Vulnerability mechanics
References
6- rpyc.readthedocs.io/en/latest/docs/security.htmlnvdExploitVendor AdvisoryWEB
- github.com/advisories/GHSA-pj4g-4488-wmxmghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2019-16328ghsaADVISORY
- lists.opensuse.org/opensuse-security-announce/2020-05/msg00046.htmlnvdBroken LinkWEB
- lists.opensuse.org/opensuse-security-announce/2020-06/msg00004.htmlnvdBroken LinkWEB
- github.com/tomerfiliba-org/rpyc/security/advisories/GHSA-pj4g-4488-wmxmghsaWEB
News mentions
0No linked articles in our index yet.