CVE-2020-15801: Netapp Max Data
Critical severity, CVSS 9.8. EPSS: 3.5% chance of exploitation in the next 30 days.
In Python 3.8.4, sys.path restrictions specified in a python38._pth file are ignored, allowing code to be loaded from arbitrary locations. The <executable-name>._pth file (e.g., the python._pth file) is not affected.
Affected products
- Netapp Max Data: affected versions not specified
- Python Python: from 3.7.0, before 3.7.9 (fixed in 3.7.9); from 3.8.0, before 3.8.5 (fixed in 3.8.5)
Published 2020-07-17. Last modified 2026-06-17.