Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-gcjf-29m9-888q: PaddlePaddle vulnerable to Code Injection

Code injection in paddle.audio.functional.get_window in PaddlePaddle 2.4.0-rc0 allows arbitrary code execution. A patch is available on the develop branch of the repository and anticipated to be part of a 2.4 release.

ghsa
#git

PaddlePaddle vulnerable to Code Injection

Critical severity GitHub Reviewed Published Dec 7, 2022 • Updated Dec 7, 2022

Related news

CVE-2022-46742: Paddle/pdsa-2022-002.md at develop · PaddlePaddle/Paddle

Code injection in paddle.audio.functional.get_window in PaddlePaddle 2.4.0-rc0 allows arbitrary code execution.