CVE-2024-21642
Users hosting versions D-Tale prior to 3.9.0 publicly can be vulnerable to server-side request forgery (SSRF), allowing attackers to access files on the server.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.71%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
D-Tale is a visualizer for Pandas data structures. Users hosting versions D-Tale prior to 3.9.0 publicly can be vulnerable to server-side request forgery (SSRF), allowing attackers to access files on the server. Users should upgrade to version 3.9.0, where the `Load From the Web` input is turned off by default. The only workaround for versions earlier than 3.9.0 is to only host D-Tale to trusted users.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.71% probability · 52th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-918
- Affected
- man/d-tale
- Source
- security-advisories@github.com
References
- https://github.com/man-group/dtale/commit/954f6be1a06ff8629ead2c85c6e3f8e2196b3df2Patch
- https://github.com/man-group/dtale/security/advisories/GHSA-7hfx-h3j3-rwq4Patch, Vendor Advisory
- https://github.com/man-group/dtale?tab=readme-ov-file#load-data--sample-datasetsProduct
- https://github.com/man-group/dtale/commit/954f6be1a06ff8629ead2c85c6e3f8e2196b3df2Patch
- https://github.com/man-group/dtale/security/advisories/GHSA-7hfx-h3j3-rwq4Patch, Vendor Advisory
- https://github.com/man-group/dtale?tab=readme-ov-file#load-data--sample-datasetsProduct
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.