streamlit-geospatial是一个适用于地理空间应用的 streamlit 多页应用程序。 streamlit-geospatial 存在安全漏洞,该漏洞源于 pages/1_??_Timelapse.py 中的 vis_params 变量接受用户输入,该输入随后在 eval 函数中使用,从而导致远程代码执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| opengeos | streamlit-geospatial | < c4f81d9616d40c60584e36abb15300853a66e489 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2024-41114 | 9.8 CRITICAL | Remote code execution in streamlit geospatial in pages/1_📷_Timelapse.py MODIS Gap filled L |
| CVE-2024-41120 | 9.8 CRITICAL | streamlit-geospatial blind SSRF in pages/9_🔲_Vector_Data_Visualization.py |
| CVE-2024-41115 | 9.8 CRITICAL | Remote code execution in streamlit geospatial in pages/1_📷_Timelapse.py MODIS Ocean Color |
| CVE-2024-41119 | 9.8 CRITICAL | streamlit-geospatial remote code execution in pages/8_🏜️_Raster_Data_Visualization.py |
| CVE-2024-41113 | 9.8 CRITICAL | Remote code execution in streamlit geospatial in pages/1_📷_Timelapse.py Any Earth Engine I |
| CVE-2024-41112 | 9.8 CRITICAL | Remote code execution in streamlit geospatial in pages/1_📷_Timelapse.py Any Earth Engine I |
| CVE-2024-41117 | 9.8 CRITICAL | Remote code execution in streamlit geospatial in pages/10_🌍_Earth_Engine_Datasets.py |
| CVE-2024-41118 | 7.5 HIGH | streamlit-geospatial blind SSRF in pages/7_📦_Web_Map_Service.py |
No comments yet