CVE-2024-49048: TorchGeo Remote Code Execution Vulnerability
Overview
- Severity
- High (CVSS 8.1)
- CVSS Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
- Category
- Remote Code Execution
- Exploit Status
- Not Exploited
- Exploitation Likelihood
- Less Likely
- Patch Tuesday
- 2024-Nov
- Released
- 2024-11-12
- EPSS Score
- 0.51% (percentile: 66.4%)
FAQ
According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?
Successful exploitation of this vulnerability requires an attacker to take additional actions prior to exploitation to prepare the target environment.
Affected Products (1)
Open Source Software
Security Updates (1)
Acknowledgments
<a href="https://zpbrent.github.io/">Peng Zhou (zpbrent)</a> with Shanghai University
Revision History
- 2024-11-12: Information published.