Количество 7
Количество 7
CVE-2024-27758
In RPyC before 6.0.0, when a server exposes a method that calls the attribute named __array__ for a client-provided netref (e.g., np.array(client_netref)), a remote attacker can craft a class that results in remote code execution.
CVE-2024-27758
In RPyC before 6.0.0, when a server exposes a method that calls the attribute named __array__ for a client-provided netref (e.g., np.array(client_netref)), a remote attacker can craft a class that results in remote code execution.
CVE-2024-27758
In RPyC before 6.0.0, when a server exposes a method that calls the attribute named __array__ for a client-provided netref (e.g., np.array(client_netref)), a remote attacker can craft a class that results in remote code execution.
CVE-2024-27758
In RPyC before 6.0.0, when a server exposes a method that calls the at ...
openSUSE-SU-2024:0082-1
Security update for python-rpyc
GHSA-h5cg-53g7-gqjw
RPyC's missing security check results in code execution when using numpy.array on the server-side.
BDU:2024-02523
Уязвимость компонента netref Python-библиотеки RPyC, позволяющая нарушителю выполнить произвольный код
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2024-27758 In RPyC before 6.0.0, when a server exposes a method that calls the attribute named __array__ for a client-provided netref (e.g., np.array(client_netref)), a remote attacker can craft a class that results in remote code execution. | CVSS3: 8.4 | 3% Низкий | почти 2 года назад | |
CVE-2024-27758 In RPyC before 6.0.0, when a server exposes a method that calls the attribute named __array__ for a client-provided netref (e.g., np.array(client_netref)), a remote attacker can craft a class that results in remote code execution. | CVSS3: 8.5 | 3% Низкий | почти 2 года назад | |
CVE-2024-27758 In RPyC before 6.0.0, when a server exposes a method that calls the attribute named __array__ for a client-provided netref (e.g., np.array(client_netref)), a remote attacker can craft a class that results in remote code execution. | CVSS3: 8.4 | 3% Низкий | почти 2 года назад | |
CVE-2024-27758 In RPyC before 6.0.0, when a server exposes a method that calls the at ... | CVSS3: 8.4 | 3% Низкий | почти 2 года назад | |
openSUSE-SU-2024:0082-1 Security update for python-rpyc | 3% Низкий | почти 2 года назад | ||
GHSA-h5cg-53g7-gqjw RPyC's missing security check results in code execution when using numpy.array on the server-side. | CVSS3: 8.5 | 3% Низкий | почти 2 года назад | |
BDU:2024-02523 Уязвимость компонента netref Python-библиотеки RPyC, позволяющая нарушителю выполнить произвольный код | CVSS3: 8.5 | 3% Низкий | почти 2 года назад |
Уязвимостей на страницу