Описание
Qiskit IBM Runtime is an environment that streamlines quantum computations and provides optimal implementations of the Qiskit quantum computing SDK. Starting in version 0.1.0 and prior to version 0.21.2, deserializing json data using qiskit_ibm_runtime.RuntimeDecoder can lead to arbitrary code execution given a correctly formatted input string. Version 0.21.2 contains a fix for this issue.
Ссылки
- Issue Tracking
- Issue Tracking
- ExploitVendor Advisory
- Issue Tracking
- Issue Tracking
- ExploitVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 0.1.0 (включая) до 0.21.2 (исключая)
cpe:2.3:a:ibm:qiskit_ibm_runtime:*:*:*:*:*:*:*:*
EPSS
Процентиль: 19%
0.00061
Низкий
5.3 Medium
CVSS3
7.8 High
CVSS3
Дефекты
CWE-502
Связанные уязвимости
CVSS3: 5.3
github
почти 2 года назад
`qiskit_ibm_runtime.RuntimeDecoder` can execute arbitrary code
EPSS
Процентиль: 19%
0.00061
Низкий
5.3 Medium
CVSS3
7.8 High
CVSS3
Дефекты
CWE-502