CVE-2024-21642
CVSS V2 None
CVSS V3 None
Description
D-Tale is a visualizer for Pandas data structures. Users hosting versions D-Tale prior to 3.9.0 publicly can be vulnerable to server-side request forgery (SSRF), allowing attackers to access files on the server. Users should upgrade to version 3.9.0, where the `Load From the Web` input is turned off by default. The only workaround for versions earlier than 3.9.0 is to only host D-Tale to trusted users.
Overview
- CVE ID
- CVE-2024-21642
- Assigner
- GitHub_M
- Vulnerability Status
- PUBLISHED
- Published Version
- 2024-01-05T21:11:41.528Z
- Last Modified Date
- 2024-01-05T21:11:41.528Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://github.com/man-group/dtale/security/advisories/GHSA-7hfx-h3j3-rwq4 | x_refsource_CONFIRM |
https://github.com/man-group/dtale/commit/954f6be1a06ff8629ead2c85c6e3f8e2196b3df2 | x_refsource_MISC |
https://github.com/man-group/dtale?tab=readme-ov-file#load-data--sample-datasets | x_refsource_MISC |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2024-21642 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21642 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-06-26 15:22:46 | Added to TrackCVE |