PT-2024-15921 · Unknown · Van Der Schaar Lab Temporai

Bayuncao

·

Published

2024-01-26

·

Updated

2024-05-17

·

CVE-2024-0936

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions van der Schaar LAB TemporAI version 0.0.3
Description A critical vulnerability was found in the function load from file of the component PKL File Handler, leading to deserialization. The attack can be launched remotely. The vendor was contacted and confirmed the existence of the issue. A patch is planned to be released.
Recommendations For van der Schaar LAB TemporAI version 0.0.3, consider disabling the load from file function of the PKL File Handler as a temporary workaround until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2024-0936
PYSEC-2024-21

Affected Products

Van Der Schaar Lab Temporai