D-Tale is a visualizer for Pandas data structures. Users hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. Users should upgrade to version 3.14.1 where the "Custom Filter" input is turned off by default.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-2849 | D-Tale is a visualizer for Pandas data structures. Users hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. Users should upgrade to version 3.14.1 where the "Custom Filter" input is turned off by default. |
Github GHSA |
GHSA-pw44-4h99-wqff | D-Tale vulnerable to Remote Code Execution through the Query input on Chart Builder |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 20 Sep 2024 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Man
Man d-tale |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:man:d-tale:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Man
Man d-tale |
Tue, 10 Sep 2024 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 10 Sep 2024 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | D-Tale is a visualizer for Pandas data structures. Users hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. Users should upgrade to version 3.14.1 where the "Custom Filter" input is turned off by default. | |
| Title | D-Tale allows Remote Code Execution through the Query input on Chart Builder | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-09-10T18:56:57.922Z
Reserved: 2024-09-02T16:00:02.423Z
Link: CVE-2024-45595
Updated: 2024-09-10T18:56:53.140Z
Status : Analyzed
Published: 2024-09-10T16:15:21.970
Modified: 2024-09-20T19:59:02.963
Link: CVE-2024-45595
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA