PT-2024-15922 · Van Der Schaar · Synthcity

Bayuncao

·

Published

2024-01-26

·

Updated

2024-05-17

·

CVE-2024-0937

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions van der Schaar LAB synthcity version 0.2.9
Description A critical issue has been found in the function load from file of the component PKL File Handler, leading to deserialization. The attack may be launched remotely. The vendor was contacted and confirmed the existence of the issue. A patch is planned to be released.
Recommendations For van der Schaar LAB synthcity version 0.2.9, consider disabling the load from file function of the PKL File Handler until a patch is available. Wait for the official patch release planned for February 2024.

Exploit

Fix

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2024-0937
GHSA-4957-7VHP-7V59

Affected Products

Synthcity