Vulnerability Details
Basic Information
| Title | Security Bulletin: IBM Watson Speech Services Cartridge v4.8.8 is vulnerable to an arbitrary code execution in Jinja [CVE-2024-56326] |
|---|---|
| Type | ibm |
| Published | 2025-05-01T17:28:33 |
| Last Seen | 2025-05-01T18:56:37 |
| CVSS Score | 7.8 (HIGH) |
CVSS v3 Details
| Attack Vector | LOCAL |
|---|---|
| Attack Complexity | LOW |
| Privileges Required | LOW |
| User Interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality Impact | HIGH |
| Integrity Impact | HIGH |
| Availability Impact | HIGH |
CVE Information
| CVE IDs | CVE-2024-56326 |
|---|---|
| CWE | |
| Bulletin Family | software |
Description
Summary IBM Watson Speech Services Cartridge is vulnerable to an arbitrary code execution in Jinja, due to an oversight in how the Jinja sandboxed environment detects calls to str.format, which allows an attacker that controls the content of a…
Impact Assessment
| Base Score | 7.8 |
|---|---|
| Severity | HIGH |