Command Injection Vulnerability in PaddlePaddle Framework
CVE-2024-0815

8.8HIGH

Key Information:

Vendor
CVE Published:
7 March 2024

What is CVE-2024-0815?

A command injection vulnerability has been identified in the PaddlePaddle framework, specifically within the 'paddle.utils.download._wget_download' function. This flaw enables attackers to exploit the system by bypassing security filters, allowing unauthorized commands to be executed. As a result, users of PaddlePaddle version 2.6.0 are at risk. Organizations utilizing this version should take immediate action to mitigate potential security threats by implementing the latest patches and reviewing their security configurations.

Affected Version(s)

paddlepaddle/paddle <= unspecified

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.