216.73.217.22

CVE-2024-27321

· Published 12/09/2024 13:15 · Modified 20/09/2024 17:06

Labels: CVE-2024-27321 2024-09-126f8de1f0-f67e-45a6-b68f-98777fdb759cCVE-2024-27321CWE-1236CWE-95

Essential information

Published
12/09/2024 13:15
Modified
20/09/2024 17:06
Author
Creator
CVSS
7.8 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CVSS metrics

Description

An arbitrary code execution vulnerability exists in versions 0.0.8 and newer of the Refuel Autolabel library because of the way its multilabel classification tasks handle provided CSV files. If a user creates a multilabel classification task using a maliciously crafted CSV file containing Python code, the code will be passed to an eval function which executes it.

NVD status

Status
Analyzed — CVE has been recently published to the CVE List and has been received by the NVD.
Source
6f8de1f0-f67e-45a6-b68f-98777fdb759c
NVD
View on NVD

Affected products (CPE)

ProductCPE
refuel / autolabel cpe:2.3:a:refuel:autolabel:*:*:*:*:*:*:*:*

References