Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4cv3-v7pv-rfhf

Опубликовано: 20 мар. 2025
Источник: github
Github: Прошло ревью
CVSS3: 9.1

Описание

PyTorch Lightning path traversal vulnerability

In lightning-ai/pytorch-lightning version 2.3.2, a vulnerability exists in the LightningApp when running on a Windows host. The vulnerability occurs at the /api/v1/upload_file/ endpoint, allowing an attacker to write or overwrite arbitrary files by providing a crafted filename. This can lead to potential remote code execution (RCE) by overwriting critical files or placing malicious files in sensitive locations.

Пакеты

Наименование

pytorch-lightning

pip
Затронутые версииВерсия исправления

< 2.4.0

2.4.0

EPSS

Процентиль: 76%
0.00976
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 9.1
nvd
11 месяцев назад

In lightning-ai/pytorch-lightning version 2.3.2, a vulnerability exists in the `LightningApp` when running on a Windows host. The vulnerability occurs at the `/api/v1/upload_file/` endpoint, allowing an attacker to write or overwrite arbitrary files by providing a crafted filename. This can lead to potential remote code execution (RCE) by overwriting critical files or placing malicious files in sensitive locations.

EPSS

Процентиль: 76%
0.00976
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-434