Intel

AIKIDO-2024-10118

torchserve is vulnerable to Arbitrary File Write

Arbitrary File WriteCVE-2024-35198 Published Jun 4, 2024

75

High Risk

This Affects:

pythontorchserve
0.1.1 - 0.10.0
Fixed in 0.11.0
Are you affected? Scan for Free

TL;DR

Affected versions of torchserve are vulnerable to a file write issue. Despite validating the URL, the targeted file via /models?url=<file_location> is still added to the models_store folder.

Who does this affect?

You are affected if you are use a vulnerable version of torchserve.

Background info

torchserve is vulnerable to Arbitrary File Write in versions 0.1.1 - 0.10.0.

How to fix this

Upgrade torchserve to the patch version (version 0.11.0).

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform