This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-6848 This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 26 Mar 2025 18:15:00 +0000

Type Values Removed Values Added
Title Command Injection in pandas-dev/pandas pandas: Command Injection in pandas-dev/pandas
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 26 Mar 2025 17:15:00 +0000

Type Values Removed Values Added
Description A command injection vulnerability exists in the `pandas.DataFrame.query` function of pandas-dev/pandas versions up to and including v2.2.2. This vulnerability allows an attacker to execute arbitrary commands on the server by crafting a malicious query. The issue arises from the improper validation of user-supplied input in the `query` function when using the 'python' engine, leading to potential remote command execution. This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Sat, 22 Mar 2025 13:45:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Thu, 20 Mar 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 20 Mar 2025 10:15:00 +0000

Type Values Removed Values Added
Description A command injection vulnerability exists in the `pandas.DataFrame.query` function of pandas-dev/pandas versions up to and including v2.2.2. This vulnerability allows an attacker to execute arbitrary commands on the server by crafting a malicious query. The issue arises from the improper validation of user-supplied input in the `query` function when using the 'python' engine, leading to potential remote command execution.
Title Command Injection in pandas-dev/pandas
Weaknesses CWE-94
References
Metrics cvssV3_0

{'score': 8.4, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: REJECTED

Assigner: @huntr_ai

Published:

Updated: 2025-03-26T17:02:39.383Z

Reserved: 2024-10-11T18:22:53.185Z

Link: CVE-2024-9880

cve-icon Vulnrichment

Updated:

cve-icon NVD

Status : Rejected

Published: 2025-03-20T10:15:50.300

Modified: 2025-03-26T17:15:25.453

Link: CVE-2024-9880

cve-icon Redhat

Severity : Important

Publid Date: 2025-03-20T10:09:04Z

Links: CVE-2024-9880 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses