Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-8020

Опубликовано: 20 мар. 2025
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

A vulnerability in lightning-ai/pytorch-lightning version 2.3.2 allows an attacker to cause a denial of service by sending an unexpected POST request to the /api/v1/state endpoint of LightningApp. This issue occurs due to improper handling of unexpected state values, which results in the server shutting down.

A flaw was found in PyTorch Lightning. This vulnerability allows an attacker to cause a denial of service via an unexpected POST request to the /api/v1/state endpoint, leading to improper handling of state values and server shutdown.

Отчет

Only Red Hat OpenShift AI 2.16 is impacted by this issue.

Меры по смягчению последствий

Implementing an input validation on the server-side for filter invalid POST requests to the /api/v1/state endpoint avoiding malicious requests.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift AI (RHOAI)rhoai/odh-codeflare-operator-rhel8Not affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=2353669pytorch-lightning: Denial of Service in lightning-ai/pytorch-lightning

EPSS

Процентиль: 19%
0.0006
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
10 месяцев назад

A vulnerability in lightning-ai/pytorch-lightning version 2.3.2 allows an attacker to cause a denial of service by sending an unexpected POST request to the `/api/v1/state` endpoint of `LightningApp`. This issue occurs due to improper handling of unexpected state values, which results in the server shutting down.

CVSS3: 7.5
github
10 месяцев назад

PyTorch Lightning denial of service vulnerability

EPSS

Процентиль: 19%
0.0006
Низкий

7.5 High

CVSS3