CVE-2024-27322

Public on 2024-04-29
Modified on 2024-05-02
Description
Deserialization of untrusted data can occur in the R statistical programming language, on any version starting at 1.4.0 up to and not including 4.4.0, enabling a maliciously crafted RDS (R Data Serialization) formatted file or R package to run arbitrary code on an end user’s system when interacted with.
Severity
Important severity
Important
CVSS v3 Base Score
8.8
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 1 R 2024-06-19 ALAS-2024-1940 Fixed
Amazon Linux 2 - R3.4 Extra R 2024-06-28 ALAS2R3.4-2024-001 Fixed
Amazon Linux 2 - R4 Extra R 2024-06-19 ALAS2R4-2024-002 Fixed
Amazon Linux 2023 R 2024-06-06 ALAS2023-2024-638 Fixed

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
NVD CVSSv3 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H