CyberzSOC

Publication detail
← Back to advisories & guidance

CERT/CC Reports R Programming Language Vulnerability ↗ source

May 1, 2024 CISA Alert

Summary

A cyber threat actor could exploit this vulnerability to take control of an affected system. Users and administrators are encouraged to review the following advisories and apply the necessary updates: Hidden Layer Blog: R-Bitrary Code Execution--Vulnerability in R’s Deserialization Comprehensive R Archive Network This product is provided subject to this Notification and this Privacy & Use policy.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2024-27322 8.8 High The R Project R Deserialization of untrusted data can occur in the R statistical programming language, on any version starting at 1.4.0 up to and not including 4.4.0…

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

No KEV-catalogued vendors are named in this publication.