QID 996859
Date Published: 2024-01-24
QID 996859: Python (Pip) Security Update for paddlepaddle (GHSA-chj7-w3f6-cvfj)
The vulnerability arises from the way the url parameter is incorporated into the command string without proper validation or sanitization. If the url is constructed from untrusted sources, an attacker could potentially inject malicious commands.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-chj7-w3f6-cvfj for updates and patch information.
Vendor References
- GHSA-chj7-w3f6-cvfj -
github.com/advisories/GHSA-chj7-w3f6-cvfj
CVEs related to QID 996859
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-chj7-w3f6-cvfj | paddlepaddle |
|