Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mrvr-7493-pfq3

Опубликовано: 20 мар. 2025
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Aim Path Traversal vulnerability

In version 3.22.0 of aimhubio/aim, the LocalFileManager._cleanup function in the aim tracking server accepts a user-specified glob-pattern for deleting files. The function does not verify that the matched files are within the directory managed by LocalFileManager, allowing a maliciously crafted glob-pattern to lead to arbitrary file deletion.

Пакеты

Наименование

aim

pip
Затронутые версииВерсия исправления

<= 3.22.0

Отсутствует

EPSS

Процентиль: 59%
0.00384
Низкий

7.5 High

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 7.5
nvd
11 месяцев назад

In version 3.22.0 of aimhubio/aim, the LocalFileManager._cleanup function in the aim tracking server accepts a user-specified glob-pattern for deleting files. The function does not verify that the matched files are within the directory managed by LocalFileManager, allowing a maliciously crafted glob-pattern to lead to arbitrary file deletion.

EPSS

Процентиль: 59%
0.00384
Низкий

7.5 High

CVSS3

Дефекты

CWE-22