Command injection when ingesting a remote Kaggle dataset due to a lack of input sanitization in the ingest_kaggle() API
Metrics
Affected Vendors & Products
References
History
Mon, 25 Nov 2024 13:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Deeplake
Deeplake deeplake |
|
Weaknesses | CWE-78 | |
CPEs | cpe:2.3:a:deeplake:deeplake:3.9.10:*:*:*:*:*:*:* | |
Vendors & Products |
Deeplake
Deeplake deeplake |
|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: JFROG
Published: 2024-07-04T11:58:21.520Z
Updated: 2024-11-25T12:51:41.531Z
Reserved: 2024-07-04T10:45:00.510Z
Link: CVE-2024-6507

Updated: 2024-08-01T21:41:03.966Z

Status : Awaiting Analysis
Published: 2024-07-04T12:15:03.963
Modified: 2024-11-25T13:15:07.517
Link: CVE-2024-6507

No data.