PT-2022-27677 · Unknown · Paddlepaddle
Published
2022-11-26
·
Updated
2022-12-01
·
CVE-2022-45908
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
PaddlePaddle versions prior to 2.4
Description
The issue arises from the
paddle.audio.functional.get window function calling eval on a user-supplied winstr, leading to potential code injection and arbitrary code execution.Recommendations
For versions prior to 2.4, consider disabling the
paddle.audio.functional.get window function until a patch is available. Restrict access to this function to minimize the risk of exploitation. Avoid using user-supplied input for the winstr variable in the affected function until the issue is resolved. Update to version 2.4 or later to resolve the issue.Exploit
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Paddlepaddle