R Programming Bug Exposes Orgs to Vast Supply Chain Risk
ID: b4109698-afce-5fe9-96be-3d00d2e9cca3
STIX ID: report--b4109698-afce-5fe9-96be-3d00d2e9cca3
Feed Name: Dark Reading
Threat Score
A high-severity deserialization vulnerability in R (CVE-2024-27322, CVSS 8.8) allows attackers to craft RDS files or packages containing promise objects that execute arbitrary R code when loaded, enabling remote code execution. HiddenLayer reported the issue and maintainers fixed it in R 4.4.0, but the report warns of broad supply-chain exposure given the large ecosystems (CRAN, R-Forge, Bioconductor) used by data scientists and organizations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
