CVE-2024-0815
Command injection in paddle.utils.download.wgetdownload (bypass filter) in paddlepaddle/paddle 2.6.0
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://nvd.nist.gov/vuln/detail/CVE-2024-0815, https://github.com/PaddlePaddle/Paddle/commit/4c0888d7b8f10405e2e79adc41c224264f93e816, https://github.com/PaddlePaddle/Paddle, https://huntr.com/bounties/83bf8191-b259-4b24-8ec9-0115d7c05350, https://pypi.org/project/paddlepaddle, https://github.com/advisories/GHSA-qqv2-35q8-p2g2