Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:47445
HistoryJun 10, 2024 - 10:06 a.m.

Unsafe Deserialization

2024-06-1010:06:26
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
1
skops
vulnerability
deserialization
validation
model
arbitrary code execution
maliciously crafted

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

7.5 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.0%

skops is vulnerable to Unsafe Deserialization. This vulnerability is due to insufficient validation during model deserialization, which can result in arbitrary code execution when a user loads a maliciously crafted model.

CPENameOperatorVersion
skopsle0.9.0
skopsle0.9.0

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

7.5 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.0%