漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
LeRobot Unsafe Deserialization Remote Code Execution via gRPC
Vulnerability Description
LeRobot through 0.5.1 contains an unsafe deserialization vulnerability in the async inference pipeline where pickle.loads() is used to deserialize data received over unauthenticated gRPC channels without TLS in the policy server and robot client components. An unauthenticated network-reachable attacker can achieve arbitrary code execution on the server or client by sending a crafted pickle payload through the SendPolicyInstructions, SendObservations, or GetActions gRPC calls.
CVSS Information
N/A
Vulnerability Type
可信数据的反序列化
Vulnerability Title
lerobot 代码问题漏洞
Vulnerability Description
lerobot是Hugging Face开源的一个机器人编程库。 LeRobot 0.5.1及之前版本存在代码问题漏洞,该漏洞源于异步推理管道中的不安全反序列化,其中pickle.loads()用于反序列化通过未经身份验证的gRPC通道接收的数据,允许未经身份验证的网络可达攻击者通过发送特制pickle有效载荷实现任意代码执行。
CVSS Information
N/A
Vulnerability Type
N/A