Intel

AIKIDO-2024-10332

kedro is vulnerable to Remote Code Execution (RCE)

Remote Code Execution (RCE)CVE-2024-9701 Published Oct 11, 2024

91

Critical Risk

This Affects:

pythonkedro
0.18.4 - 0.19.8
Fixed in 0.19.9
Are you affected? Scan for Free

TL;DR

Affected versions of the package are vulnerable to Remote Code Execution (RCE) through malicious shelve file uploads in Kedro's ShelveStore. Attackers can exploit this vulnerability by uploading a specially crafted file, which may execute arbitrary code on the server when processed.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

kedro is vulnerable to Remote Code Execution (RCE) in versions 0.18.4 - 0.19.8.

How to fix this

Upgrade the kedro library to the patch version.