CVE-2024-12994
CVSS 3.1 Score 6.3 of 10 (medium)
Details
Published Dec 28, 2024
CWE ID 502
CWE ID 20
Summary
CVE-2024-12994 is a critical vulnerability impacting the running-elephant Datart 1.0.0-rc3 component. The issue lies within the File Upload component's "import" file and specifically the "extractModel" function. An attacker can exploit this deserialization vulnerability by manipulating the argument file and launching the attack remotely. The exploit has been disclosed to the public, increasing the risk for potential attacks. Unfortunately, the vendor has not responded to the disclosure despite early notification.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.