Description
streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb15300853a66e489, the `vis_params` variable on line 1254 in `pages/1_📷_Timelapse.py` takes user input, which is later used in the `eval()` function on line 1345, leading to remote code execution. Commit c4f81d9616d40c60584e36abb15300853a66e489 fixes this issue.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-38935 | streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb15300853a66e489, the `vis_params` variable on line 1254 in `pages/1_📷_Timelapse.py` takes user input, which is later used in the `eval()` function on line 1345, leading to remote code execution. Commit c4f81d9616d40c60584e36abb15300853a66e489 fixes this issue. |
References
History
Mon, 26 Aug 2024 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Opengeos
Opengeos streamlit-geospatial |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:opengeos:streamlit-geospatial:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Opengeos
Opengeos streamlit-geospatial |
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-02T04:46:52.561Z
Reserved: 2024-07-15T15:53:28.322Z
Link: CVE-2024-41116
Updated: 2024-08-02T04:46:52.561Z
Status : Modified
Published: 2024-07-26T21:15:13.237
Modified: 2024-11-21T09:32:15.997
Link: CVE-2024-41116
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD