Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-3447 | D-Tale is a visualizer for pandas data structures. Prior to version 3.16.1, users hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. Users should upgrade to version 3.16.1 where the `update-settings` endpoint blocks the ability for users to update the `enable_custom_filters` flag. The only workaround for versions earlier than 3.16.1 is to only host D-Tale to trusted users. |
Github GHSA |
GHSA-832w-fhmw-w4f4 | D-Tale allows Remote Code Execution through the Custom Filter Input |
Fri, 13 Dec 2024 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 13 Dec 2024 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | D-Tale is a visualizer for pandas data structures. Prior to version 3.16.1, users hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. Users should upgrade to version 3.16.1 where the `update-settings` endpoint blocks the ability for users to update the `enable_custom_filters` flag. The only workaround for versions earlier than 3.16.1 is to only host D-Tale to trusted users. | |
| Title | D-Tale allows Remote Code Execution through the Custom Filter Input | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-12-13T18:48:43.721Z
Reserved: 2024-12-12T15:03:39.205Z
Link: CVE-2024-55890
Updated: 2024-12-13T18:48:38.031Z
Status : Deferred
Published: 2024-12-13T18:15:22.373
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-55890
No data.
OpenCVE Enrichment
Updated: 2025-07-12T16:01:21Z
EUVD
Github GHSA