PyAnsys Geometry is a Python client library for the Ansys Geometry service and other CAD Ansys products. On file src/ansys/geometry/core/connection/product_instance.py, upon calling this method _start_program directly, users could exploit its usage to perform malicious operations on the current machine where the script is ran. This vulnerability is fixed in 0.3.3 and 0.4.12.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-03-26T02:50:34.984Z

Updated: 2024-08-05T20:27:31.415Z

Reserved: 2024-03-18T17:07:00.094Z

Link: CVE-2024-29189

cve-icon Vulnrichment

Updated: 2024-08-02T01:10:54.820Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-03-26T03:15:13.150

Modified: 2024-03-26T12:55:05.010

Link: CVE-2024-29189

cve-icon Redhat

No data.