CVE-2024-41116
CVSS v3.1
9.8 (Critical)
EPSS
0.06 % (26th)
Affected Products
1
NVD Status
Analyzed
streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb15300853a66e489, the vis_params
variable on line 1254 in pages/1_?_Timelapse.py
takes user input, which is later used in the eval()
function on line 1345, leading to remote code execution. Commit c4f81d9616d40c60584e36abb15300853a66e489 fixes this issue.
Weaknesses
- CWE-20
- Improper Input Validation
- CWE-NVD-noinfo
- CVE Status
- PUBLISHED
- NVD Status
- Analyzed
- CNA
- GitHub, Inc.
- Published Date
-
2024-07-26 21:15:13
(6 weeks ago) - Updated Date
-
2024-08-26 17:33:24
(12 days ago)
Affected Products
Loading...
Loading...
Loading...
Configuration #1
|
Loading...
Loading...
Loading...
Loading...