CVE-2024-0936

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-0936
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-0936.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-0936
Aliases
Published
2024-01-26T17:15:11Z
Modified
2024-10-11T07:52:19Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

A vulnerability classified as critical was found in vanderSchaar LAB TemporAI 0.0.3. Affected by this vulnerability is the function loadfromfile of the component PKL File Handler. The manipulation leads to deserialization. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-252181 was assigned to this vulnerability. NOTE: The vendor was contacted early and confirmed immediately the existence of the issue. A patch is planned to be released in February 2024.

References

Affected packages

Git / github.com/vanderschaarlab/temporai

Affected ranges

Type
GIT
Repo
https://github.com/vanderschaarlab/temporai
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected