Description
Llama Stack prior to revision 7a8aa775e5a267cf8660d83140011a0b7f91e005 used pickle as a serialization format for socket communication, potentially allowing for remote code execution. Socket communication has been changed to use JSON instead.
Published: 2024-10-23
Score: 6.3 Medium
EPSS: 3.0% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Oct 2024 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Meta Platforms Inc
Meta Platforms Inc llama Stack
CPEs cpe:2.3:a:meta_platforms_inc:llama_stack:*:*:*:*:*:*:*:*
Vendors & Products Meta Platforms Inc
Meta Platforms Inc llama Stack
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 23 Oct 2024 13:45:00 +0000

Type Values Removed Values Added
Description Llama Stack prior to revision 7a8aa775e5a267cf8660d83140011a0b7f91e005 used pickle as a serialization format for socket communication, potentially allowing for remote code execution. Socket communication has been changed to use JSON instead.
References

Subscriptions

Meta Platforms Inc Llama Stack
cve-icon MITRE

Status: PUBLISHED

Assigner: facebook

Published:

Updated: 2024-10-24T18:26:22.699Z

Reserved: 2024-10-21T15:18:52.624Z

Link: CVE-2024-50050

cve-icon Vulnrichment

Updated: 2024-10-24T18:26:08.699Z

cve-icon NVD

Status : Deferred

Published: 2024-10-23T14:15:05.087

Modified: 2026-04-15T00:35:42.020

Link: CVE-2024-50050

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses

No weakness.