PT-2022-27677 · Unknown · Paddlepaddle

Published

2022-11-26

·

Updated

2022-12-01

·

CVE-2022-45908

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PaddlePaddle versions prior to 2.4
Description The issue arises from the paddle.audio.functional.get window function calling eval on a user-supplied winstr, leading to potential code injection and arbitrary code execution.
Recommendations For versions prior to 2.4, consider disabling the paddle.audio.functional.get window function until a patch is available. Restrict access to this function to minimize the risk of exploitation. Avoid using user-supplied input for the winstr variable in the affected function until the issue is resolved. Update to version 2.4 or later to resolve the issue.

Exploit

Fix

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2022-45908
GHSA-83G7-8FCH-P37M

Affected Products

Paddlepaddle