CVE-2024-10190 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

Horovod versions up to and including v0.28.1 are vulnerable to unauthenticated remote code execution. The vulnerability is due to improper handling of base64-en…
Critical CVSS: 9.8

CVE-2024-10190

Horovod versions up to and including v0.28.1 are vulnerable to unauthenticated remote code execution. The vulnerability is due to improper handling of base64-encoded data in the `ElasticRendezvousHandler`, a subclass of `KVStoreHandler`. Specifically, the `_put_value` method in `ElasticRendezvousHandler` calls `codec.loads_base64(value)`, which eventually invokes `cloudpickle.loads(decoded)`. This allows an attacker to send a malicious pickle object via a PUT request, leading to arbitrary code execution on the server.
Vendor
Horovod
Product
Horovod
CWE
CWE-502
Yayın Tarihi
2025-03-20 10:15:15
Güncelleme
2025-12-11 18:19:19
Source Identifier
security@huntr.dev
KEV Date Added
-

Kategoriler

Referanslar