Description
PaddlePaddle before 2.5.0 has a command injection in fs.py. This resulted in the ability to execute arbitrary commands on the operating system.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-0195 | PaddlePaddle before 2.5.0 has a command injection in fs.py. This resulted in the ability to execute arbitrary commands on the operating system.\n |
Github GHSA |
GHSA-9q9v-qgwx-84mr | Command injection in PaddlePaddle |
References
History
Wed, 23 Oct 2024 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Baidu
Published:
Updated: 2024-10-23T15:40:52.801Z
Reserved: 2023-07-24T07:55:02.091Z
Link: CVE-2023-38673
Updated: 2024-08-02T17:46:56.509Z
Status : Modified
Published: 2023-07-26T12:15:09.640
Modified: 2026-06-17T06:10:55.410
Link: CVE-2023-38673
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
EUVD
Github GHSA