
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2024-6507 is a command injection vulnerability discovered in Deep Lake's ingest_kaggle() API. The vulnerability was disclosed on July 4, 2024, and affects the Deep Lake AI-oriented database platform. The issue stems from a lack of input sanitization when ingesting remote Kaggle datasets (JFrog Research, NVD).
The vulnerability exists in the ingest_kaggle() method where the tag parameter is passed to the _exec_command method without proper input filtering. The issue has been assigned a CVSS v3.1 base score of 8.1 (HIGH) with the vector string CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H. It has been classified under CWE-94 (Improper Control of Generation of Code) and CWE-78 (Improper Neutralization of Special Elements used in an OS Command) (JFrog Research, Hacker News).
When exploited, this vulnerability allows attackers to perform remote code execution on the server, potentially compromising the integrity, availability, and confidentiality of available resources. This is particularly critical for applications that expose Kaggle dataset upload functionality to external users (JFrog Research).
The vulnerability can be exploited by passing maliciously crafted input to the tag parameter in the ingest_kaggle() method. A proof of concept demonstrates that an attacker can execute arbitrary commands by injecting OS commands through the tag parameter (JFrog Research).
The vulnerability has been addressed in version 3.9.11 of Deep Lake. Users are advised to upgrade to this version or later to protect against this security issue (JFrog Research).
The vulnerability was discovered by Natan Nehorai of the JFrog Security Research Team and has been highlighted as part of a broader investigation into security flaws in popular machine learning toolkits (Hacker News).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."