Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mvp8-9qgw-vf58

Опубликовано: 20 мар. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

A remote code execution vulnerability exists in open-mmlab/mmdetection version v3.3.0. The vulnerability is due to the use of the pickle.loads() function in the all_reduce_dict() distributed training API without proper sanitization. This allows an attacker to execute arbitrary code by broadcasting a malicious payload to the distributed training network.

A remote code execution vulnerability exists in open-mmlab/mmdetection version v3.3.0. The vulnerability is due to the use of the pickle.loads() function in the all_reduce_dict() distributed training API without proper sanitization. This allows an attacker to execute arbitrary code by broadcasting a malicious payload to the distributed training network.

EPSS

Процентиль: 81%
0.0158
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-502

Связанные уязвимости

CVSS3: 9.8
nvd
11 месяцев назад

A remote code execution vulnerability exists in open-mmlab/mmdetection version v3.3.0. The vulnerability is due to the use of the `pickle.loads()` function in the `all_reduce_dict()` distributed training API without proper sanitization. This allows an attacker to execute arbitrary code by broadcasting a malicious payload to the distributed training network.

EPSS

Процентиль: 81%
0.0158
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-502