Описание
Pymatgen (Python Materials Genomics) is an open-source Python library for materials analysis. A critical security vulnerability exists in the JonesFaithfulTransformation.from_transformation_str() method within the pymatgen library prior to version 2024.2.20. This method insecurely utilizes eval() for processing input, enabling execution of arbitrary code when parsing untrusted input. Version 2024.2.20 fixes this issue.
Ссылки
- Broken Link
- Patch
- ExploitVendor Advisory
- Broken Link
- Patch
- ExploitVendor Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
EPSS
9.3 Critical
CVSS3
7.8 High
CVSS3
Дефекты
Связанные уязвимости
Pymatgen (Python Materials Genomics) is an open-source Python library for materials analysis. A critical security vulnerability exists in the `JonesFaithfulTransformation.from_transformation_str()` method within the `pymatgen` library prior to version 2024.2.20. This method insecurely utilizes `eval()` for processing input, enabling execution of arbitrary code when parsing untrusted input. Version 2024.2.20 fixes this issue.
Pymatgen (Python Materials Genomics) is an open-source Python library ...
pymatgen vulnerable to arbitrary code execution when parsing a maliciously crafted JonesFaithfulTransformation transformation_string
EPSS
9.3 Critical
CVSS3
7.8 High
CVSS3