D-Tale is a visualizer for pandas data structures. Prior to version 3.16.1, users hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. Users should upgrade to version 3.16.1 where the `update-settings` endpoint blocks the ability for users to update the `enable_custom_filters` flag. The only workaround for versions earlier than 3.16.1 is to only host D-Tale to trusted users.
Metrics
Affected Vendors & Products
References
History
Fri, 13 Dec 2024 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 13 Dec 2024 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | D-Tale is a visualizer for pandas data structures. Prior to version 3.16.1, users hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. Users should upgrade to version 3.16.1 where the `update-settings` endpoint blocks the ability for users to update the `enable_custom_filters` flag. The only workaround for versions earlier than 3.16.1 is to only host D-Tale to trusted users. | |
| Title | D-Tale allows Remote Code Execution through the Custom Filter Input | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-12-13T18:00:04.173Z
Updated: 2024-12-13T18:48:43.721Z
Reserved: 2024-12-12T15:03:39.205Z
Link: CVE-2024-55890
Updated: 2024-12-13T18:48:38.031Z
Status : Received
Published: 2024-12-13T18:15:22.373
Modified: 2024-12-13T18:15:22.373
Link: CVE-2024-55890
No data.