PaddlePaddle before 2.6.0 has a command injection in get_online_pass_interval. This resulted in the ability to execute arbitrary commands on the operating system.
References
Link | Resource |
---|---|
https://github.com/PaddlePaddle/Paddle/blob/develop/security/advisory/pdsa-2023-019.md | Patch Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: Baidu
Published: 2024-01-03T08:14:55.842Z
Updated: 2024-01-03T08:14:55.842Z
Reserved: 2024-01-02T05:32:46.254Z
Link: CVE-2023-52310
JSON object: View
NVD Information
Status : Analyzed
Published: 2024-01-03T09:15:10.520
Modified: 2024-01-05T12:14:56.697
Link: CVE-2023-52310
JSON object: View
Redhat Information
No data.
CWE