CVE-2014-0485: s3ql Project s3ql

High severity, CVSS 7.5. EPSS: 4.6% chance of exploitation in the next 30 days.

S3QL 1.18.1 and earlier uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via a crafted serialized object in (1) common.py or (2) local.py in backends/.

Affected products

  • s3ql Project s3ql: up to and including 1.18.1; version 1.17 only; version 1.18 only

Published 2014-09-02. Last modified 2026-06-17.