CVE-2024-0815

HIGH8.8EPSS 0.09%

PaddlePaddle command injection in paddle.utils.download._wget_download

Published: 3/7/2024Modified: 1/21/2025

Description

Command injection in paddle.utils.download._wget_download (bypass filter) in paddlepaddle/paddle 2.6.0

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH8.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

References (4)