CVE-2024-21642

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-21642
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-21642.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-21642
Aliases
Related
Published
2024-01-05T22:15:43Z
Modified
2025-01-08T15:46:44.510072Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

D-Tale is a visualizer for Pandas data structures. Users hosting versions D-Tale prior to 3.9.0 publicly can be vulnerable to server-side request forgery (SSRF), allowing attackers to access files on the server. Users should upgrade to version 3.9.0, where the Load From the Web input is turned off by default. The only workaround for versions earlier than 3.9.0 is to only host D-Tale to trusted users.

References

Affected packages

Git / github.com/man-group/dtale

Affected ranges

Type
GIT
Repo
https://github.com/man-group/dtale
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed

Affected versions

2.*

2.14.0
2.9.0

v.*

v.1.21.1
v.1.32.1
v.1.6.9

v1.*

v1.0.0
v1.1.0
v1.1.1
v1.10.0
v1.11.0
v1.12.0
v1.13.0
v1.14.0
v1.14.1
v1.15.2
v1.16.0
v1.17.0
v1.18.0
v1.18.1
v1.18.2
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.20.0
v1.21.0
v1.22.0
v1.22.1
v1.23.0
v1.24.0
v1.25.0
v1.26.0
v1.27.0
v1.28.0
v1.28.1
v1.29.0
v1.3.0
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.3.6
v1.3.7
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.1
v1.38.0
v1.39.0
v1.4.0
v1.4.1
v1.40.1
v1.40.2
v1.41.0
v1.41.1
v1.42.0
v1.42.1
v1.43.0
v1.44.0
v1.44.1
v1.45.0
v1.46.0
v1.47.0
v1.48.0
v1.49.0
v1.5.0
v1.5.1
v1.51.0
v1.52.0
v1.53.0
v1.54.0
v1.54.1
v1.55.0
v1.56.0
v1.58.1
v1.58.2
v1.59.1
v1.6.1
v1.6.10
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.6.7
v1.6.8
v1.60.1
v1.60.2
v1.61.0
v1.7.0
v1.7.1
v1.7.11
v1.7.12
v1.7.13
v1.7.14
v1.7.15
v1.7.2
v1.7.3
v1.7.4
v1.7.5
v1.7.6
v1.7.7
v1.7.8
v1.7.9
v1.8.0
v1.8.1
v1.8.10
v1.8.11
v1.8.12
v1.8.13
v1.8.14
v1.8.15
v1.8.16
v1.8.17
v1.8.19
v1.8.7
v1.8.8
v1.9.0
v1.9.1
v1.9.2

v2.*

v2.0.0
v2.1.0
v2.1.2
v2.10.0
v2.11.0
v2.12.0
v2.12.1
v2.12.2
v2.12.3
v2.13.0
v2.14.1
v2.14.2
v2.14.3
v2.14.4
v2.15.0
v2.15.1
v2.15.2
v2.16.0
v2.2.0
v2.3.0
v2.4.0
v2.5.1
v2.6.0
v2.7.1
v2.8.0
v2.8.1
v2.9.1

v3.*

v3.0.0
v3.1.0
v3.1.4
v3.1.5
v3.1.6
v3.2.0
v3.3.0
v3.4.0
v3.5.0
v3.6.0
v3.7.0
v3.8.0
v3.8.1