Description
streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb15300853a66e489, the palette variable in `pages/1_📷_Timelapse.py` takes user input, which is later used in the `eval()` function on line 380, leading to remote code execution. Commit c4f81d9616d40c60584e36abb15300853a66e489 fixes this issue.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-38931 | streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb15300853a66e489, the palette variable in `pages/1_📷_Timelapse.py` takes user input, which is later used in the `eval()` function on line 380, leading to remote code execution. Commit c4f81d9616d40c60584e36abb15300853a66e489 fixes this issue. |
References
History
Mon, 26 Aug 2024 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Opengeos
Opengeos streamlit-geospatial |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:opengeos:streamlit-geospatial:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Opengeos
Opengeos streamlit-geospatial |
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-02T04:46:52.635Z
Reserved: 2024-07-15T15:53:28.321Z
Link: CVE-2024-41112
Updated: 2024-08-02T04:46:52.635Z
Status : Modified
Published: 2024-07-26T20:15:05.237
Modified: 2024-11-21T09:32:15.440
Link: CVE-2024-41112
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD