216.73.217.22

CVE-2024-27320

· Published 12/09/2024 13:15 · Modified 23/09/2024 13:56

Labels: CVE-2024-27320 2024-09-126f8de1f0-f67e-45a6-b68f-98777fdb759cCVE-2024-27320CWE-1236CWE-95

Essential information

Published
12/09/2024 13:15
Modified
23/09/2024 13:56
Author
Creator
CVSS
7.8 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CVSS metrics

Description

An arbitrary code execution vulnerability exists in versions 0.0.8 and newer of the Refuel Autolabel library because of the way its classification tasks handle provided CSV files. If a victim user creates a classification task using a maliciously crafted CSV file containing Python code, the code will be passed to an eval function which executes it.

NVD status

Status
Analyzed — CVE has been recently published to the CVE List and has been received by the NVD.
Source
6f8de1f0-f67e-45a6-b68f-98777fdb759c
NVD
View on NVD

Affected products (CPE)

ProductCPE
refuel / autolabel cpe:2.3:a:refuel:autolabel:*:*:*:*:*:*:*:*

References