ait-core
PyPI5 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting ait-corepage 1 of 1
- CVE-2024-35056CRITICALCVSS 9.8EG 9.82024-05-21
vulnerable: 1.0.0 ... 2.5.2 (20 versions)
NASA AIT-Core v2.5.2 was discovered to contain multiple SQL injection vulnerabilities via the query_packets and insert functions.
- CVE-2024-35057HIGHCVSS 7.5EG 7.52024-05-21
vulnerable: 1.0.0 ... 2.5.2 (20 versions)
An issue in NASA AIT-Core v2.5.2 allows attackers to execute arbitrary code via a crafted packet.
- CVE-2024-35058HIGHCVSS 7.5EG 7.52024-05-21
vulnerable: 1.0.0 ... 2.5.2 (20 versions)
An issue in the API wait function of NASA AIT-Core v2.5.2 allows attackers to execute arbitrary code via supplying a crafted string.
- CVE-2024-35059HIGHCVSS 7.5EG 9.82024-05-21
vulnerable: 1.0.0 ... 2.5.2 (20 versions)
An issue in the Pickle Python library of NASA AIT-Core v2.5.2 allows attackers to execute arbitrary commands.
- CVE-2024-35061HIGHCVSS 7.3EG 7.32024-05-21
vulnerable: 1.0.0 ... 2.5.2 (20 versions)
NASA AIT-Core v2.5.2 was discovered to use unencrypted channels to exchange data over the network, allowing attackers to execute a man-in-the-middle attack. When chained with CVE-2024-35059, the CVE in subject leads to an unauthenticated, …
Check whether ait-core is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for ait-core CVEs against the assets you own.
Start Free Scan →