Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Deserialization of untrusted data can occur in the R statistical programming language, on any version starting at 1.4.0 up to and not including 4.4.0, enabling a maliciously crafted RDS (R Data Serialization) formatted file or R package to run arbitrary code on an end user’s system when interacted with.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Vulnerability Type
可信数据的反序列化
Vulnerability Title
R statistical programming language 安全漏洞
Vulnerability Description
R statistical programming language是R Foundation基金会的一个用于统计计算和图形的免费编程语言。 R statistical programming language 1.4.0版本至4.4.0之前版本存在安全漏洞,该漏洞源于存在不受信任的数据反序列化,攻击者与最终用户的系统交互时能够运行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A