Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-57hm-8rjv-498w

Опубликовано: 25 сент. 2025
Источник: github
Github: Прошло ревью
CVSS4: 2.1
CVSS3: 6.3

Описание

ml-logger deserialization vulnerability

A vulnerability was determined in geyang ml-logger 0.10.36 and prior. Affected is the function log_handler of the file ml_logger/server.py of the component Ping Handler. This manipulation of the argument data causes deserialization. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available.

Пакеты

Наименование

ml-logger

pip
Затронутые версииВерсия исправления

<= 0.10.36

Отсутствует

EPSS

Процентиль: 27%
0.00096
Низкий

2.1 Low

CVSS4

6.3 Medium

CVSS3

Дефекты

CWE-20
CWE-502

Связанные уязвимости

CVSS3: 6.3
nvd
4 месяца назад

A vulnerability was determined in geyang ml-logger up to acf255bade5be6ad88d90735c8367b28cbe3a743. Affected is the function log_handler of the file ml_logger/server.py of the component Ping Handler. This manipulation of the argument data causes deserialization. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available.

EPSS

Процентиль: 27%
0.00096
Низкий

2.1 Low

CVSS4

6.3 Medium

CVSS3

Дефекты

CWE-20
CWE-502