CVE-2024-47833
Last modified
CVE-2024-47833 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. Taipy is an open-source Python library for easy, end-to-end application development for data scientists and machine learning engineers. In affected versions session cookies are served without Secure and HTTPOnly flags. EPSS estimates a 0.25% chance of exploitation in the next 30 days.
Description
Taipy is an open-source Python library for easy, end-to-end application development for data scientists and machine learning engineers. In affected versions session cookies are served without Secure and HTTPOnly flags. This issue has been addressed in release version 4.0.0 and all users are advised to upgrade. There are no known workarounds for this vulnerability.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Avaiga | Taipy | < 4.0.0 |
References
- https://github.com/Avaiga/taipy/security/advisories/GHSA-r3jq-4r5c-j9hpExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-47833?
How severe is CVE-2024-47833?
How do I fix CVE-2024-47833?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-47828ampache is a web based audio/video streaming application and…6.5
- CVE-2024-47829pnpm is a package manager. Prior to version 10.0.0, the path…6.5
- CVE-2024-4783The jQuery T(-) Countdown Widget plugin for WordPress is vul…6.4
- CVE-2024-47830Plane is an open-source project management tool. Plane uses …5.8
- CVE-2024-47831Next.js is a React Framework for the Web. Cersions on the 10…7.5
- CVE-2024-47832ssoready is a single sign on provider implemented via docker…9.8
- CVE-2024-47834GStreamer is a library for constructing graphs of media-hand…9.1
- CVE-2024-47835GStreamer is a library for constructing graphs of media-hand…7.5
- CVE-2024-47836Admidio is an open-source user management solution. Prior to…4.3
- CVE-2024-4784An issue was discovered in GitLab EE starting from version 1…5.4
- CVE-2024-47840Improper Neutralization of Input During Web Page Generation …4.8
- CVE-2024-47841Improper Limitation of a Pathname to a Restricted Directory …7.5
Are you affected by CVE-2024-47833?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
