Command injection when ingesting a remote Kaggle dataset due to a lack of input sanitization in the ingest_kaggle() API
History

Mon, 25 Nov 2024 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Deeplake
Deeplake deeplake
Weaknesses CWE-78
CPEs cpe:2.3:a:deeplake:deeplake:3.9.10:*:*:*:*:*:*:*
Vendors & Products Deeplake
Deeplake deeplake
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: JFROG

Published: 2024-07-04T11:58:21.520Z

Updated: 2024-11-25T12:51:41.531Z

Reserved: 2024-07-04T10:45:00.510Z

Link: CVE-2024-6507

cve-icon Vulnrichment

Updated: 2024-08-01T21:41:03.966Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-07-04T12:15:03.963

Modified: 2024-11-25T13:15:07.517

Link: CVE-2024-6507

cve-icon Redhat

No data.