Описание
FreeCAD is a free and open-source multiplatform 3D parametric modeler. From 0.19 until 1.1.1, FreeCAD's BIM Workbench contains an eval() call on untrusted data from SVG template files. When a user creates a TechDraw page from a malicious SVG template, arbitrary Python code executes. The vulnerable code is in src/Mod/BIM/bimcommands/BimTDPage.py (line 87). This issue is fixed in version 1.1.1.
EPSS
Процентиль: 3%
0.00134
Низкий
7.8 High
CVSS3
Дефекты
CWE-95
Связанные уязвимости
CVSS3: 7.8
debian
1 день назад
FreeCAD is a free and open-source multiplatform 3D parametric modeler. ...
EPSS
Процентиль: 3%
0.00134
Низкий
7.8 High
CVSS3
Дефекты
CWE-95