Vulnerability Description
PyAnsys Geometry is a Python client library for the Ansys Geometry service and other CAD Ansys products. On file src/ansys/geometry/core/connection/product_instance.py, upon calling this method _start_program directly, users could exploit its usage to perform malicious operations on the current machine where the script is ran. This vulnerability is fixed in 0.3.3 and 0.4.12.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ansys | Pyansys Geometry | >= 0.3.0, < 0.3.3 |
Related Weaknesses (CWE)
References
- https://bandit.readthedocs.io/en/1.7.8/plugins/b602_subprocess_popen_with_shell_Technical Description
- https://github.com/ansys/pyansys-geometry/blob/52cba1737a8a7812e5430099f715fa216Patch
- https://github.com/ansys/pyansys-geometry/commit/902071701c4f3a8258cbaa46c28dc0aPatch
- https://github.com/ansys/pyansys-geometry/commit/f82346b9432b06532e84f3278125f58Patch
- https://github.com/ansys/pyansys-geometry/pull/1076Issue Tracking
- https://github.com/ansys/pyansys-geometry/pull/1077Issue Tracking
- https://github.com/ansys/pyansys-geometry/security/advisories/GHSA-38jr-29fh-w9vExploitVendor Advisory
- https://bandit.readthedocs.io/en/1.7.8/plugins/b602_subprocess_popen_with_shell_Technical Description
- https://github.com/ansys/pyansys-geometry/blob/52cba1737a8a7812e5430099f715fa216Patch
- https://github.com/ansys/pyansys-geometry/commit/902071701c4f3a8258cbaa46c28dc0aPatch
- https://github.com/ansys/pyansys-geometry/commit/f82346b9432b06532e84f3278125f58Patch
- https://github.com/ansys/pyansys-geometry/pull/1076Issue Tracking
- https://github.com/ansys/pyansys-geometry/pull/1077Issue Tracking
- https://github.com/ansys/pyansys-geometry/security/advisories/GHSA-38jr-29fh-w9vExploitVendor Advisory
FAQ
What is CVE-2024-29189?
CVE-2024-29189 is a vulnerability with a CVSS score of 7.4 (HIGH). PyAnsys Geometry is a Python client library for the Ansys Geometry service and other CAD Ansys products. On file src/ansys/geometry/core/connection/product_instance.py, upon calling this method _start...
How severe is CVE-2024-29189?
CVE-2024-29189 has been rated HIGH with a CVSS base score of 7.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-29189?
Check the references section above for vendor advisories and patch information. Affected products include: Ansys Pyansys Geometry.