Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f892-3gpj-v83f

Опубликовано: 14 мар. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

greykite v1.0.0 was discovered to contain an arbitrary file upload vulnerability in the load_obj function at /templates/pickle_utils.py. This vulnerability allows attackers to execute arbitrary code via uploading a crafted file.

greykite v1.0.0 was discovered to contain an arbitrary file upload vulnerability in the load_obj function at /templates/pickle_utils.py. This vulnerability allows attackers to execute arbitrary code via uploading a crafted file.

EPSS

Процентиль: 28%
0.00101
Низкий

7.5 High

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 7.5
nvd
почти 2 года назад

greykite v1.0.0 was discovered to contain an arbitrary file upload vulnerability in the load_obj function at /templates/pickle_utils.py. This vulnerability allows attackers to execute arbitrary code via uploading a crafted file.

EPSS

Процентиль: 28%
0.00101
Низкий

7.5 High

CVSS3

Дефекты

CWE-434