漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
RCE in the package conda-forge-metadata
Vulnerability Description
conda-forge-metadata provides programatic access to conda-forge's metadata. conda-forge-metadata uses an optional dependency - "conda-oci-mirror" which was neither present on the PyPi repository nor registered by any entity. If conda-oci-mirror is taken over by a threat actor, it can result in remote code execution.
CVSS Information
N/A
Vulnerability Type
从非可信控制范围包含功能例程
Vulnerability Title
conda-forge-metadata 安全漏洞
Vulnerability Description
conda-forge-metadata是conda-forge开源的一个对 conda-forge 元数据的程序化访问。 conda-forge-metadata 0.4.1及之前版本存在安全漏洞,该漏洞源于依赖劫持,可能导致远程代码执行。
CVSS Information
N/A
Vulnerability Type
N/A