CVE-2014-0485: s3ql Project s3ql
High severity, CVSS 7.5. EPSS: 4.6% chance of exploitation in the next 30 days.
S3QL 1.18.1 and earlier uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via a crafted serialized object in (1) common.py or (2) local.py in backends/.
Affected products
- s3ql Project s3ql: up to and including 1.18.1; version 1.17 only; version 1.18 only
Published 2014-09-02. Last modified 2026-06-17.