Описание
An issue was discovered in ModelScope 1.25.0 allowing attackers to execute arbitrary code via crafted module listed in the configuration file (dey_mini.yaml) under the key ['nnet']['module'].
Ссылки
EPSS
Процентиль: 42%
0.00522
Низкий
7.3 High
CVSS3
8.1 High
CVSS3
Дефекты
CWE-94
CWE-502
Связанные уязвимости
CVSS3: 8.1
redhat
3 месяца назад
An issue was discovered in ModelScope 1.25.0 allowing attackers to execute arbitrary code via crafted module listed in the configuration file (dey_mini.yaml) under the key ['nnet']['module'].
CVSS3: 7.3
github
3 месяца назад
ModelScope is vulnerable to arbitrary code injection via a crafted module
EPSS
Процентиль: 42%
0.00522
Низкий
7.3 High
CVSS3
8.1 High
CVSS3
Дефекты
CWE-94
CWE-502