mirror of
https://github.com/0xMarcio/cve.git
synced 2025-05-05 18:27:17 +00:00
1.2 KiB
1.2 KiB
CVE-2024-41112
Description
streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb15300853a66e489, the palette variable in pages/1_📷_Timelapse.py
takes user input, which is later used in the eval()
function on line 380, leading to remote code execution. Commit c4f81d9616d40c60584e36abb15300853a66e489 fixes this issue.
POC
Reference
4b89495f3b/pages/1_%F0%9F%93%B7_Timelapse.py (L373-L376)
4b89495f3b/pages/1_%F0%9F%93%B7_Timelapse.py (L380)
- https://securitylab.github.com/advisories/GHSL-2024-100_GHSL-2024-108_streamlit-geospatial/
Github
No PoCs found on GitHub currently.