Apache Arrow是美国阿帕奇(Apache)基金会的一款用于内存数据处理的跨语言开发平台。该平台支持C、C++、C#、Go和Java等编程语言,并提供进程间通信等功能。 Apache Arrow 0.14.0版本至14.0.0版本存在安全漏洞,该漏洞源于存在不受信任的数据反序列化,允许攻击者执行任意代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | PyArrow | 0.14.0 ~ 14.0.0 | - |
|
| Apache Software Foundation | PyArrow | 0.14.0 ~ 14.0.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | PyArrow Flight RPC from v0.14.0 through v14.0.0 allows remote attackers to execute arbitrary code via a maliciously crafted Python-defined extension type. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2023/CVE-2023-47248.yaml | POC Details |
| 2 | Repo containing pyarrow 14.0.0, vulnerable to RCE - CVE-2023-47248 | https://github.com/Prodigysec/pyarrow-CVE-2023-47248 | POC Details |
No public POC found.
Login to generate AI POCNo comments yet