Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2024-23346

Опубликовано: 21 фев. 2024
Источник: ubuntu
Приоритет: medium
EPSS Средний
CVSS3: 9.3

Описание

Pymatgen (Python Materials Genomics) is an open-source Python library for materials analysis. A critical security vulnerability exists in the JonesFaithfulTransformation.from_transformation_str() method within the pymatgen library prior to version 2024.2.20. This method insecurely utilizes eval() for processing input, enabling execution of arbitrary code when parsing untrusted input. Version 2024.2.20 fixes this issue.

РелизСтатусПримечание
bionic

DNE

devel

not-affected

2024.10.29+dfsg1-5
esm-apps/jammy

needed

esm-infra/focal

DNE

focal

DNE

jammy

needed

mantic

ignored

end of life, was needs-triage
noble

DNE

oracular

not-affected

2024.1.27+dfsg1-7ubuntu1
plucky

not-affected

2024.10.29+dfsg1-5

Показывать по

EPSS

Процентиль: 97%
0.41597
Средний

9.3 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.3
nvd
почти 2 года назад

Pymatgen (Python Materials Genomics) is an open-source Python library for materials analysis. A critical security vulnerability exists in the `JonesFaithfulTransformation.from_transformation_str()` method within the `pymatgen` library prior to version 2024.2.20. This method insecurely utilizes `eval()` for processing input, enabling execution of arbitrary code when parsing untrusted input. Version 2024.2.20 fixes this issue.

CVSS3: 9.3
debian
почти 2 года назад

Pymatgen (Python Materials Genomics) is an open-source Python library ...

CVSS3: 9.3
github
почти 2 года назад

pymatgen vulnerable to arbitrary code execution when parsing a maliciously crafted JonesFaithfulTransformation transformation_string

EPSS

Процентиль: 97%
0.41597
Средний

9.3 Critical

CVSS3