CVE-2024-12994

CVSS 3.1 Score 6.3 of 10 (medium)

Details

Published Dec 28, 2024
CWE ID 502
CWE ID 20

Summary

CVE-2024-12994 is a critical vulnerability impacting the running-elephant Datart 1.0.0-rc3 component. The issue lies within the File Upload component's "import" file and specifically the "extractModel" function. An attacker can exploit this deserialization vulnerability by manipulating the argument file and launching the attack remotely. The exploit has been disclosed to the public, increasing the risk for potential attacks. Unfortunately, the vendor has not responded to the disclosure despite early notification.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share