Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-27758

Опубликовано: 12 мар. 2024
Источник: redhat
CVSS3: 8.5

Описание

In RPyC before 6.0.0, when a server exposes a method that calls the attribute named array for a client-provided netref (e.g., np.array(client_netref)), a remote attacker can craft a class that results in remote code execution.

Отчет

This vulnerability doesn't affect any support Red Hat product.

Дополнительная информация

Статус:

Important
Дефект:
CWE-358->CWE-913
https://bugzilla.redhat.com/show_bug.cgi?id=2269242python-rpyc: Remote attacker can craft a class, resulting in remote code execution

8.5 High

CVSS3

Связанные уязвимости

CVSS3: 8.4
ubuntu
почти 2 года назад

In RPyC before 6.0.0, when a server exposes a method that calls the attribute named __array__ for a client-provided netref (e.g., np.array(client_netref)), a remote attacker can craft a class that results in remote code execution.

CVSS3: 8.4
nvd
почти 2 года назад

In RPyC before 6.0.0, when a server exposes a method that calls the attribute named __array__ for a client-provided netref (e.g., np.array(client_netref)), a remote attacker can craft a class that results in remote code execution.

CVSS3: 8.4
debian
почти 2 года назад

In RPyC before 6.0.0, when a server exposes a method that calls the at ...

suse-cvrf
почти 2 года назад

Security update for python-rpyc

CVSS3: 8.5
github
почти 2 года назад

RPyC's missing security check results in code execution when using numpy.array on the server-side.

8.5 High

CVSS3