CVE-2024-29032
Last modified
CVE-2024-29032 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. Qiskit IBM Runtime is an environment that streamlines quantum computations and provides optimal implementations of the Qiskit quantum computing SDK. Starting in version 0.1.0 and prior to version 0.21.2, deserializing json data using `qiskit_ibm_runtime.RuntimeDecoder` can lead to arbitrary code execution given a correctly formatted input string. EPSS estimates a 0.37% chance of exploitation in the next 30 days.
Description
Qiskit IBM Runtime is an environment that streamlines quantum computations and provides optimal implementations of the Qiskit quantum computing SDK. Starting in version 0.1.0 and prior to version 0.21.2, deserializing json data using `qiskit_ibm_runtime.RuntimeDecoder` can lead to arbitrary code execution given a correctly formatted input string. Version 0.21.2 contains a fix for this issue.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Qiskit Ibm Runtime | >= 0.1.0, < 0.21.2 |
References
- https://github.com/Qiskit/qiskit-ibm-runtime/security/advisories/GHSA-x4x5-jv3x-9c7mExploit, Vendor Advisory
- https://github.com/Qiskit/qiskit-ibm-runtime/security/advisories/GHSA-x4x5-jv3x-9c7mExploit, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-29032?
How severe is CVE-2024-29032?
How do I fix CVE-2024-29032?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-29027Parse Server is an open source backend that can be deployed …9
- CVE-2024-29028memos is a privacy-first, lightweight note-taking service. I…5.3
- CVE-2024-29029memos is a privacy-first, lightweight note-taking service. I…6.1
- CVE-2024-2903A vulnerability was found in Tenda AC7 15.03.06.44. It has b…8.8
- CVE-2024-29030memos is a privacy-first, lightweight note-taking service. I…5.3
- CVE-2024-29031Meshery is an open source, cloud native manager that enables…7.5
- CVE-2024-29033OAuthenticator provides plugins for JupyterHub to use common…9.1
- CVE-2024-29034CarrierWave is a solution for file uploads for Rails, Sinatr…6.1
- CVE-2024-29035Umbraco is an ASP.NET CMS. Failing webhooks logs are availab…5.3
- CVE-2024-29036Saleor Storefront is software for building e-commerce experi…6.5
- CVE-2024-29037datahub-helm provides the Kubernetes Helm charts for deployi…9.1
- CVE-2024-29038tpm2-tools is the source repository for the Trusted Platform…3.3
Are you affected by CVE-2024-29032?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
