Frost Ming
5 exploits
Active since Oct 2023
BentoML has Information Disclosure in `bentoml build` via symlink traversal in the build context
CVSS 5.5
BentoML >=1.3.4 <1.4.3 - Unauthenticated Remote Code Execution via Insecure Deserialization
CVSS 9.8
PDM 2.0.0-2.9.3 - Dependency Confusion via Malicious pdm.lock File
CVSS 7.8
BentoML 1.2.0-1.2.4 - Remote Code Execution via Insecure Deserialization
CVSS 10.0
BentoML < 1.4.34 - Path Traversal via bentofile.yaml Configuration Fields
CVSS 7.4