CVE-2024-45595 Information
Sep 11, 2024
cve
Description
D-Tale is a visualizer for Pandas data structures. Users hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. Users should upgrade to version 3.14.1 where the \Custom Filter\ input is turned off by default.
Reference
https://github.com/man-group/dtale/security/advisories/GHSA-pw44-4h99-wqff https://github.com/man-group/dtale/commit/b6e30969390520d1400b55acbb13e5487b8472e8 https://github.com/man-group/dtale#custom-filter
Share on: