CVE-2024-9701
CVSS 3.0 Score 9.8 of 10 (critical)
Details
Published Mar 20, 2025
CWE ID 502
Summary
CVE-2024-9701 is a newly discovered Remote Code Execution (RCE) vulnerability affecting the Kedro ShelveStore class in version 0.19.8. This issue allows an attacker to execute arbitrary Python code through malicious payloads during deserialization using the Python pickle module. The ShelveStore class, which manages session data using the shelve module, is the vulnerable component. An adversary can craft a malicious payload, store it in a shelve file, and gain RCE when the payload is deserialized. Potentially, this could lead to a full system compromise.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.