Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:45805
HistoryMar 08, 2024 - 7:25 a.m.

Remote Code Execution (RCE)

2024-03-0807:25:43
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
6
paddlepaddle
hdfsclient
rce
vulnerability
user input
code injection

CVSS3

9.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

LOW

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L

AI Score

8.2

Confidence

High

EPSS

0

Percentile

9.0%

paddlepaddle is vulnerable to Remote Code Execution (RCE). The vulnerability is due to improper handling of user input in the HDFSClient class within fs.py.This allows an attacker to execute arbitrary commands by injecting malicious input, resulting in Code Injection.

CVSS3

9.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

LOW

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L

AI Score

8.2

Confidence

High

EPSS

0

Percentile

9.0%