Логотип exploitDog
bind:CVE-2024-9701
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-9701

Количество 2

Количество 2

nvd логотип

CVE-2024-9701

11 месяцев назад

A Remote Code Execution (RCE) vulnerability has been identified in the Kedro ShelveStore class (version 0.19.8). This vulnerability allows an attacker to execute arbitrary Python code via deserialization of malicious payloads, potentially leading to a full system compromise. The ShelveStore class uses Python's shelve module to manage session data, which relies on pickle for serialization. Crafting a malicious payload and storing it in the shelve file can lead to RCE when the payload is deserialized.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-747f-ww56-4q4h

11 месяцев назад

Kedro deserialization vulnerability

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-9701

A Remote Code Execution (RCE) vulnerability has been identified in the Kedro ShelveStore class (version 0.19.8). This vulnerability allows an attacker to execute arbitrary Python code via deserialization of malicious payloads, potentially leading to a full system compromise. The ShelveStore class uses Python's shelve module to manage session data, which relies on pickle for serialization. Crafting a malicious payload and storing it in the shelve file can lead to RCE when the payload is deserialized.

CVSS3: 9.8
1%
Низкий
11 месяцев назад
github логотип
GHSA-747f-ww56-4q4h

Kedro deserialization vulnerability

CVSS3: 9.8
1%
Низкий
11 месяцев назад

Уязвимостей на страницу