CVE-2024-1651

CRITICAL10.0EPSS 80.6%

Deserialization of Untrusted Data in Torrentpier

Published: 2/20/2024Modified: 2/12/2025

Description

Torrentpier version 2.4.1 allows executing arbitrary commands on the server. This is possible because the application is vulnerable to insecure deserialization.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1CRITICAL10.0CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

References (3)