CVE-2024-43598

GHSA-2586-f3p4-hq84 HIGH
Published November 12, 2024

LightGBM Remote Code Execution...

Full analysis pending. Showing NVD description excerpt.

Affected Systems

Package Ecosystem Vulnerable Range Patched
lightgbm pip >= 1.0.0, < 4.6.0 4.6.0
lightgbm pip No patch

Severity & Risk

CVSS 3.1
8.1 / 10
EPSS
1.6%
chance of exploitation in 30 days
KEV Status
Not in KEV
Sophistication
N/A

Recommended Action

Patch available

Update lightgbm to version 4.6.0

Compliance Impact

Compliance analysis pending. Sign in for full compliance mapping when available.

Technical Details

NVD Description

LightGBM Remote Code Execution Vulnerability

CVSS Vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Timeline

Published
November 12, 2024
Last Modified
February 18, 2025
First Seen
November 12, 2024