Code injection in paddle.audio.functional.get_window
in PaddlePaddle 2.4.0-rc0 allows arbitrary code execution. A patch is available on the develop
branch of the repository and anticipated to be part of a 2.4 release.
{ "github_reviewed_at": "2022-12-07T14:55:31Z", "severity": "CRITICAL", "nvd_published_at": "2022-12-07T09:15:00Z", "cwe_ids": [ "CWE-94" ], "github_reviewed": true }