{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2024-21642","assignerOrgId":"a0819718-46f1-4df5-94e2-005712e83aaa","state":"PUBLISHED","assignerShortName":"GitHub_M","dateReserved":"2023-12-29T03:00:44.958Z","datePublished":"2024-01-05T21:11:41.528Z","dateUpdated":"2025-06-17T20:29:14.066Z"},"containers":{"cna":{"title":"D-Tale server-side request forgery through Web uploads","problemTypes":[{"descriptions":[{"cweId":"CWE-918","lang":"en","description":"CWE-918: Server-Side Request Forgery (SSRF)","type":"CWE"}]}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","version":"3.1"}}],"references":[{"name":"https://github.com/man-group/dtale/security/advisories/GHSA-7hfx-h3j3-rwq4","tags":["x_refsource_CONFIRM"],"url":"https://github.com/man-group/dtale/security/advisories/GHSA-7hfx-h3j3-rwq4"},{"name":"https://github.com/man-group/dtale/commit/954f6be1a06ff8629ead2c85c6e3f8e2196b3df2","tags":["x_refsource_MISC"],"url":"https://github.com/man-group/dtale/commit/954f6be1a06ff8629ead2c85c6e3f8e2196b3df2"},{"name":"https://github.com/man-group/dtale?tab=readme-ov-file#load-data--sample-datasets","tags":["x_refsource_MISC"],"url":"https://github.com/man-group/dtale?tab=readme-ov-file#load-data--sample-datasets"}],"affected":[{"vendor":"man-group","product":"dtale","versions":[{"version":"< 3.9.0","status":"affected"}]}],"providerMetadata":{"orgId":"a0819718-46f1-4df5-94e2-005712e83aaa","shortName":"GitHub_M","dateUpdated":"2024-01-05T21:11:41.528Z"},"descriptions":[{"lang":"en","value":"D-Tale is a visualizer for Pandas data structures. Users hosting versions D-Tale prior to 3.9.0 publicly can be vulnerable to server-side request forgery (SSRF), allowing attackers to access files on the server. Users should upgrade to version 3.9.0, where the `Load From the Web` input is turned off by default. The only workaround for versions earlier than 3.9.0 is to only host D-Tale to trusted users."}],"source":{"advisory":"GHSA-7hfx-h3j3-rwq4","discovery":"UNKNOWN"}},"adp":[{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-01T22:27:35.919Z"},"title":"CVE Program Container","references":[{"name":"https://github.com/man-group/dtale/security/advisories/GHSA-7hfx-h3j3-rwq4","tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://github.com/man-group/dtale/security/advisories/GHSA-7hfx-h3j3-rwq4"},{"name":"https://github.com/man-group/dtale/commit/954f6be1a06ff8629ead2c85c6e3f8e2196b3df2","tags":["x_refsource_MISC","x_transferred"],"url":"https://github.com/man-group/dtale/commit/954f6be1a06ff8629ead2c85c6e3f8e2196b3df2"},{"name":"https://github.com/man-group/dtale?tab=readme-ov-file#load-data--sample-datasets","tags":["x_refsource_MISC","x_transferred"],"url":"https://github.com/man-group/dtale?tab=readme-ov-file#load-data--sample-datasets"}]},{"metrics":[{"other":{"type":"ssvc","content":{"id":"CVE-2024-21642","role":"CISA Coordinator","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"version":"2.0.3","timestamp":"2024-01-08T15:25:38.388086Z"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2025-06-17T20:29:14.066Z"}}]}}