Deserialization of untrusted data can occur in the R...
High severity
Unreviewed
Published
Apr 29, 2024
to the GitHub Advisory Database
•
Updated Feb 13, 2025
Description
Published by the National Vulnerability Database
Apr 29, 2024
Published to the GitHub Advisory Database
Apr 29, 2024
Last updated
Feb 13, 2025
Deserialization of untrusted data can occur in the R statistical programming language, on any version starting at 1.4.0 up to and not including 4.4.0, enabling a maliciously crafted RDS (R Data Serialization) formatted file or R package to run arbitrary code on an end user’s system when interacted with.
References