CVE-2025-27510

conda-forge-metadata provides programatic access to conda-forge's metadata. conda-forge-metadata uses an optional dependency - "conda-oci-mirror" which was neither present on the PyPi repository nor registered by any entity. If conda-oci-mirror is taken over by a threat actor, it can result in remote code execution.
CVSS

No CVSS.

Configurations

No configuration.

History

05 Mar 2025, 17:15

Type Values Removed Values Added
Summary
  • (es) conda-forge-metadata proporciona acceso programático a los metadatos de conda-forge. conda-forge-metadata utiliza una dependencia opcional, "conda-oci-mirror", que no estaba presente en el repositorio de PyPi ni estaba registrada por ninguna entidad. Si un actor de amenazas toma el control de conda-oci-mirror, puede resultar en la ejecución remota de código.
References () https://github.com/conda-forge/conda-forge-metadata/security/advisories/GHSA-vwfh-m3q7-9jpw - () https://github.com/conda-forge/conda-forge-metadata/security/advisories/GHSA-vwfh-m3q7-9jpw -

04 Mar 2025, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-04 22:15

Updated : 2025-03-05 17:15


NVD link : CVE-2025-27510

Mitre link : CVE-2025-27510

CVE.ORG link : CVE-2025-27510


JSON object : View

Products Affected

No product.

CWE
CWE-829

Inclusion of Functionality from Untrusted Control Sphere