This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
History

Wed, 26 Mar 2025 18:15:00 +0000

Type Values Removed Values Added
Title Command Injection in pandas-dev/pandas pandas: Command Injection in pandas-dev/pandas
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 26 Mar 2025 17:15:00 +0000

Type Values Removed Values Added
Description A command injection vulnerability exists in the `pandas.DataFrame.query` function of pandas-dev/pandas versions up to and including v2.2.2. This vulnerability allows an attacker to execute arbitrary commands on the server by crafting a malicious query. The issue arises from the improper validation of user-supplied input in the `query` function when using the 'python' engine, leading to potential remote command execution. This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Sat, 22 Mar 2025 13:45:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Thu, 20 Mar 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 20 Mar 2025 10:15:00 +0000

Type Values Removed Values Added
Description A command injection vulnerability exists in the `pandas.DataFrame.query` function of pandas-dev/pandas versions up to and including v2.2.2. This vulnerability allows an attacker to execute arbitrary commands on the server by crafting a malicious query. The issue arises from the improper validation of user-supplied input in the `query` function when using the 'python' engine, leading to potential remote command execution.
Title Command Injection in pandas-dev/pandas
Weaknesses CWE-94
References
Metrics cvssV3_0

{'score': 8.4, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: REJECTED

Assigner: @huntr_ai

Published: 2025-03-20T10:09:04.353Z

Updated: 2025-03-26T17:02:39.383Z

Reserved: 2024-10-11T18:22:53.185Z

Link: CVE-2024-9880

cve-icon Vulnrichment

Updated:

cve-icon NVD

Status : Rejected

Published: 2025-03-20T10:15:50.300

Modified: 2025-03-26T17:15:25.453

Link: CVE-2024-9880

cve-icon Redhat

Severity : Important

Publid Date: 2025-03-20T10:09:04Z

Links: CVE-2024-9880 - Bugzilla