Description

Deserialization of untrusted data can occur in the R statistical programming language, on any version starting at 1.4.0 up to and not including 4.4.0, enabling a maliciously crafted RDS (R Data Serialization) formatted file or R package to run arbitrary code on an end user’s system when interacted with.

INFO

Published Date :

2024-04-29T13:02:37.062Z

Last Modified :

2025-02-13T17:46:26.987Z

Source :

HiddenLayer
AFFECTED PRODUCTS

The following products are affected by CVE-2024-27322 vulnerability.

Vendors Products
R Project
  • R

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact