Upstream information
Description
A command injection vulnerability exists in the `pandas.DataFrame.query` function of pandas-dev/pandas versions up to and including v2.2.2. This vulnerability allows an attacker to execute arbitrary commands on the server by crafting a malicious query. The issue arises from the improper validation of user-supplied input in the `query` function when using the 'python' engine, leading to potential remote command execution.SUSE information
Overall state of this security issue: Pending
This issue is currently rated as having important severity.
CNA (Huntr.dev) | SUSE | |
---|---|---|
Base Score | 8.4 | 8.4 |
Vector | CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Attack Vector | Local | Local |
Attack Complexity | Low | Low |
Privileges Required | None | None |
User Interaction | None | None |
Scope | Unchanged | Unchanged |
Confidentiality Impact | High | High |
Integrity Impact | High | High |
Availability Impact | High | High |
CVSSv3 Version | 3 | 3.1 |
SUSE Timeline for this CVE
CVE page created: Thu Mar 20 12:02:16 2025CVE page last modified: Fri Mar 21 19:53:44 2025