Intel

AIKIDO-2024-10180

lightning is vulnerable to Unrestricted Upload of File with Dangerous Type

Unrestricted Upload of File with Dangerous TypeCVE-2024-5980 Published Jul 15, 2024

91

Critical Risk

This Affects:

pythonlightning
0.2 - 2.3.2
Fixed in 2.3.3
Are you affected? Scan for Free

TL;DR

A vulnerability in the /v1/runs API endpoint of lightning-ai/pytorch-lightning allows attackers to exploit path traversal when extracting tar.gz files. When the LightningApp runs with the plugin_server, attackers can deploy malicious tar.gz plugins that embed arbitrary files with path traversal vulnerabilities. This can lead to arbitrary files being written to any directory on the victim's local file system, potentially enabling Remote Code Execution (RCE).

Who does this affect?

You are affected if you are using a vulnerable version of the package.

Background info

lightning is vulnerable to Unrestricted Upload of File with Dangerous Type in versions 0.2 - 2.3.2.

How to fix this

Upgrade lightning to a patch version.