CVE-2024-5998 - CERT CVE
ID CVE-2024-5998
Sažetak A vulnerability in the FAISS.deserialize_from_bytes function of langchain-ai/langchain allows for pickle deserialization of untrusted data. This can lead to the execution of arbitrary commands via the os.system function. The issue affects the latest version of the product.
Reference
CVSS
Base: 5.2
Impact: 4.7
Exploitability:0.5
Pristup
VektorSloženostAutentikacija
PHYSICAL LOW LOW
Impact
PovjerljivostCjelovitostDostupnost
HIGH LOW LOW
CVSS vektor CVSS:3.0/AV:P/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:L
Zadnje važnije ažuriranje 20-09-2024 - 12:31
Objavljeno 17-09-2024 - 12:15