New R Programming Vulnerability Exposes Projects to Supply Chain Attacks

A security vulnerability has been discovered in the R programming language that could be exploited by a threat actor to create a malicious RDS (R Data Serialization) file such that it results in code execution when loaded and referenced. The flaw, assigned the CVE identifier CVE-2024-27322, "involves the use of promise objects and lazy evaluation in R," AI application security

More From Author

Sandbox Escape Vulnerabilities in Judge0 Expose Systems to Complete Takeover

Navigating the Threat Landscape: Understanding Exposure Management, Pentesting, Red Teaming and RBVM

Leave a Reply