CVE-2024-41117

CRITICAL

Opengeos Streamlit-geospatial < 2024-07-19 - Improper Input Validation

Title source: rule
STIX 2.1

Description

streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb15300853a66e489, the `vis_params` variable on line 115 in `pages/10_🌍_Earth_Engine_Datasets.py` takes user input, which is later used in the `eval()` function on line 126, leading to remote code execution. Commit c4f81d9616d40c60584e36abb15300853a66e489 fixes this issue.

Scores

CVSS v3 9.8
EPSS 0.0233
EPSS Percentile 84.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-20
Status published
Products (1)
opengeos/streamlit-geospatial < 2024-07-19
Published Jul 26, 2024
Tracked Since Feb 18, 2026