CVE-2024-29189

Source
https://cve.org/CVERecord?id=CVE-2024-29189
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-29189.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-29189
Aliases
Published
2024-03-26T02:50:34.984Z
Modified
2026-04-02T10:27:16.833131Z
Severity
  • 7.4 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
ansys-geometry-core OS Command Injection vulnerability
Details

PyAnsys Geometry is a Python client library for the Ansys Geometry service and other CAD Ansys products. On file src/ansys/geometry/core/connection/product_instance.py, upon calling this method startprogram directly, users could exploit its usage to perform malicious operations on the current machine where the script is ran. This vulnerability is fixed in 0.3.3 and 0.4.12.

Database specific
{
    "cwe_ids": [
        "CWE-78"
    ],
    "cna_assigner": "GitHub_M",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/29xxx/CVE-2024-29189.json"
}
References

Affected packages

Git / github.com/ansys/pyansys-geometry

Affected ranges

Type
GIT
Repo
https://github.com/ansys/pyansys-geometry
Events
Database specific
{
    "versions": [
        {
            "introduced": "0.3.0"
        },
        {
            "fixed": "0.3.3"
        }
    ]
}
Type
GIT
Repo
https://github.com/ansys/pyansys-geometry
Events
Database specific
{
    "versions": [
        {
            "introduced": "0.4.0"
        },
        {
            "fixed": "0.4.12"
        }
    ]
}

Affected versions

v0.*
v0.3.0
v0.3.1
v0.3.2
v0.4.0
v0.4.1
v0.4.10
v0.4.11
v0.4.2
v0.4.3
v0.4.4
v0.4.5
v0.4.6
v0.4.7
v0.4.8
v0.4.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-29189.json"