Unrated severityNVD Advisory· Published Jan 26, 2024· Updated Aug 27, 2024
van_der_Schaar LAB TemporAI PKL File load_from_file deserialization
CVE-2024-0936
Description
A vulnerability classified as critical was found in van_der_Schaar LAB TemporAI 0.0.3. Affected by this vulnerability is the function load_from_file of the component PKL File Handler. The manipulation leads to deserialization. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-252181 was assigned to this vulnerability. NOTE: The vendor was contacted early and confirmed immediately the existence of the issue. A patch is planned to be released in February 2024.
Affected products
2=0.0.3+ 1 more
- (no CPE)range: =0.0.3
- (no CPE)range: 0.0.3
Patches
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- github.com/bayuncao/vul-cve-5/blob/main/poc.pymitreexploit
- vuldb.commitresignaturepermissions-required
- vuldb.commitrevdb-entrytechnical-description
News mentions
0No linked articles in our index yet.