Описание
An arbitrary code execution vulnerability exists in versions 0.0.8 and newer of the Refuel Autolabel library because of the way its classification tasks handle provided CSV files. If a victim user creates a classification task using a maliciously crafted CSV file containing Python code, the code will be passed to an eval function which executes it.
Ссылки
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 0.0.8 (включая)
cpe:2.3:a:refuel:autolabel:*:*:*:*:*:*:*:*
EPSS
Процентиль: 21%
0.00066
Низкий
7.8 High
CVSS3
Дефекты
CWE-95
CWE-1236
Связанные уязвимости
EPSS
Процентиль: 21%
0.00066
Низкий
7.8 High
CVSS3
Дефекты
CWE-95
CWE-1236