• CVE-2024-38526

发布时间: 2024年6月28日

修改时间: 2024年7月2日

概要

pdoc provides API Documentation for Python Projects. Documentation generated with `pdoc --math` linked to JavaScript files from polyfill.io. The polyfill.io CDN has been sold and now serves malicious code. This issue has been fixed in pdoc 14.5.1.

CVSS v3 指标

NVD openEuler
CVSS评分 7.2 7.2
Attack Vector Network Network
Attack Complexity Low Low
Privileges Required None None
User Interaction None None
Scope Changed Changed
Confidentiality Low Low
Integrity None None
Availability Low Low

安全公告

公告名 概要 发布时间
KylinSec-SA-2024-2930 pdoc provides API Documentation for Python Projects. Documentation generated with `pdoc --math` linked to JavaScript files from polyfill.io. The polyfill.io CDN has been sold and now serves malicious code. This issue has been fixed in pdoc 14.5.1. 2024年6月28日

影响产品

产品 状态
KY3.4-5A pdoc Unaffected
KY3.5.2 pdoc Unaffected
V6 pdoc Unaffected