CVE-2022-45908

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
26/11/2022
Last modified:
25/04/2025

Description

In PaddlePaddle before 2.4, paddle.audio.functional.get_window is vulnerable to code injection because it calls eval on a user-supplied winstr. This may lead to arbitrary code execution.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:paddlepaddle:paddlepaddle:*:*:*:*:*:*:*:* 2.4 (excluding)