CVE-2024-0521: Code Injection in paddlepaddle/paddle

9.3 CVSS

Description

Code Injection in paddlepaddle/paddle

Classification

CVE ID: CVE-2024-0521

CVSS Base Severity: CRITICAL

CVSS Base Score: 9.3

CVSS Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Problem Types

CWE-94 Improper Control of Generation of Code

Affected Products

Vendor: paddlepaddle

Product: paddlepaddle/paddle

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.06% (probability of being exploited)

EPSS Percentile: 18.44% (scored less or equal to compared to others)

EPSS Date: 2025-05-30 (when was this score calculated)

Stakeholder-Specific Vulnerability Categorization (SSVC)

SSVC Exploitation: poc

SSVC Technical Impact: total

SSVC Automatable: false

References

https://nvd.nist.gov/vuln/detail/CVE-2024-0521
https://huntr.com/bounties/a569c64b-1e2b-4bed-a19f-47fd5a3da453

Timeline