D-Tale allows Remote Code Execution through the Query input on Chart Builder
CVE-2024-45595

9.8CRITICAL

Key Information:

Vendor

Man-group

Status
Vendor
CVE Published:
10 September 2024

What is CVE-2024-45595?

D-Tale is a powerful visualizer specifically designed for Pandas data structures. It has been identified that users who host D-Tale publicly may expose their systems to a security risk, allowing malicious actors to execute arbitrary code on the server. This vulnerability arises from the 'Custom Filter' feature, which can lead to remote code execution if left enabled. To safeguard against this vulnerability, it is crucial for users to upgrade to version 3.14.1, where the 'Custom Filter' input is disabled by default. Ensuring prompt updates and adhering to best security practices can help mitigate the risks associated with this vulnerability.

Affected Version(s)

dtale < 3.14.1

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.