CVE-2024-0521
CVSS 3.1 Score 7.8 of 10 (high)
Details
Published Jan 20, 2024
Updated: Jan 29, 2024
CWE ID 94
Summary
CVE-2024-0521 is a newly disclosed code injection vulnerability affecting the popular machine learning framework, paddlepaddle/paddle. Attackers can exploit this issue by injecting malicious code into the software, potentially leading to unauthorized data access, modification, or execution of arbitrary commands. The vulnerability arises due to insufficient input validation, allowing untrusted data to be executed within the application. Users are advised to update to the latest version of paddlepaddle as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share