CVE-2024-0937
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Jan 26, 2024
Updated: May 17, 2024
CWE ID 502
Summary
CVE-2024-0937 is a critical vulnerability affecting the PKL File Handler component in van_der_Schaar LAB's synthcity 0.2.9. The issue involves manipulation leading to deserialization in the load_from_file function, allowing remote exploitation. The vulnerability, identified as VDB-252182, has been publicly disclosed and exploits are available. The vendor has confirmed the issue and plans to release a patch in February 2024.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.