D-Tale is a visualizer for pandas data structures. Prior to version 3.16.1, users hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. Users should upgrade to version 3.16.1 where the `update-settings` endpoint blocks the ability for users to update the `enable_custom_filters` flag. The only workaround for versions earlier than 3.16.1 is to only host D-Tale to trusted users.
Metrics
Affected Vendors & Products
References
History
Fri, 13 Dec 2024 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 13 Dec 2024 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | D-Tale is a visualizer for pandas data structures. Prior to version 3.16.1, users hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. Users should upgrade to version 3.16.1 where the `update-settings` endpoint blocks the ability for users to update the `enable_custom_filters` flag. The only workaround for versions earlier than 3.16.1 is to only host D-Tale to trusted users. | |
Title | D-Tale allows Remote Code Execution through the Custom Filter Input | |
Weaknesses | CWE-79 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-12-13T18:00:04.173Z
Updated: 2024-12-13T18:48:43.721Z
Reserved: 2024-12-12T15:03:39.205Z
Link: CVE-2024-55890

Updated: 2024-12-13T18:48:38.031Z

Status : Received
Published: 2024-12-13T18:15:22.373
Modified: 2024-12-13T18:15:22.373
Link: CVE-2024-55890

No data.