CVE-2022-25882
published 2023-01-26CVE-2022-25882: Versions of the package onnx before 1.13.0 are vulnerable to Directory Traversal as the external_data field of the tensor proto can have a path to the file…
PriorityP343high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
1.61%
73.5th percentile
Versions of the package onnx before 1.13.0 are vulnerable to Directory Traversal as the external_data field of the tensor proto can have a path to the file which is outside the model current directory or user-provided directory, for example "../../../etc/passwd"
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| linuxfoundation | onnx | < 1.16.0 | 1.16.0 |
| linuxfoundation | onnx | < 1.13.0 | 1.13.0 |
| msrc | azl3_pytorch_2.2.2-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_pytorch_2.2.2-7_on_azure_linux_3.0 | — | — |
| msrc | azure_linux_3.0_arm | — | — |
| msrc | azure_linux_3.0_x64 | — | — |
| msrc | cbl2_pytorch_2.0.0-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_pytorch_2.0.0-6_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_pytorch_2.0.0-8_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| onnx | onnx | < 66b7fb630903fdcf3e83b6b6d56d82e904264a20 | 66b7fb630903fdcf3e83b6b6d56d82e904264a20 |
| onnx | onnx | <= 1.15.0 | — |
| onnx | onnx | >= 0 < 1.13.0 | 1.13.0 |
| onnx | onnx | >= 0 < 66b7fb630903fdcf3e83b6b6d56d82e904264a20 | 66b7fb630903fdcf3e83b6b6d56d82e904264a20 |
| onnx | onnx | >= 0 < 1.16.0 | 1.16.0 |
| onnx | onnx | >= 0 < f369b0e859024095d721f1d1612da5a8fa38988d | f369b0e859024095d721f1d1612da5a8fa38988d |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
ghsa7.5HIGH
osv7.5HIGH
vendor_msrc7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2024-27318: Versions of the package onnx before and including 1
osv·2024-02-23·CVSS 7.5
CVE-2024-27318 [HIGH] CVE-2024-27318: Versions of the package onnx before and including 1
Versions of the package onnx before and including 1.15.0 are vulnerable to Directory Traversal as the external_data field of the tensor proto can have a path to the file which is outside the model current directory or user-provided directory. The vulnerability occurs as a bypass for the patch added for CVE-2022-25882.
GHSA
Onnx Directory Traversal vulnerability
ghsa·2024-02-23·CVSS 7.5
CVE-2024-27318 [HIGH] CWE-22 Onnx Directory Traversal vulnerability
Onnx Directory Traversal vulnerability
Versions of the package onnx before and including 1.15.0 are vulnerable to Directory Traversal as the external_data field of the tensor proto can have a path to the file which is outside the model current directory or user-provided directory. The vulnerability occurs as a bypass for the patch added for CVE-2022-25882.
OSV
Onnx Directory Traversal vulnerability
osv·2024-02-23·CVSS 7.5
CVE-2024-27318 [HIGH] Onnx Directory Traversal vulnerability
Onnx Directory Traversal vulnerability
Versions of the package onnx before and including 1.15.0 are vulnerable to Directory Traversal as the external_data field of the tensor proto can have a path to the file which is outside the model current directory or user-provided directory. The vulnerability occurs as a bypass for the patch added for CVE-2022-25882.
GHSA
Directory Traversal in onnx
ghsa·2023-01-26
CVE-2022-25882 [HIGH] CWE-22 Directory Traversal in onnx
Directory Traversal in onnx
Versions of the package onnx before 1.13.0 are vulnerable to Directory Traversal as the external_data field of the tensor proto can have a path to the file which is outside the model current directory or user-provided directory, for example "../../../etc/passwd"
OSV
CVE-2022-25882: Versions of the package onnx before 1
osv·2023-01-26
CVE-2022-25882 CVE-2022-25882: Versions of the package onnx before 1
Versions of the package onnx before 1.13.0 are vulnerable to Directory Traversal as the external_data field of the tensor proto can have a path to the file which is outside the model current directory or user-provided directory, for example "../../../etc/passwd"
OSV
Directory Traversal in onnx
osv·2023-01-26
CVE-2022-25882 [HIGH] Directory Traversal in onnx
Directory Traversal in onnx
Versions of the package onnx before 1.13.0 are vulnerable to Directory Traversal as the external_data field of the tensor proto can have a path to the file which is outside the model current directory or user-provided directory, for example "../../../etc/passwd"
Microsoft
Versions of the package onnx before and including 1.15.0 are vulnerable to Directory Traversal as the external_data field of the tensor proto can have a path to the file which is outside the model cur
vendor_msrc·2024-02-13·CVSS 7.5
CVE-2024-27318 [HIGH] CWE-22 Versions of the package onnx before and including 1.15.0 are vulnerable to Directory Traversal as the external_data field of the tensor proto can have a path to the file which is outside the model cur
Versions of the package onnx before and including 1.15.0 are vulnerable to Directory Traversal as the external_data field of the tensor proto can have a path to the file which is outside the model current directory or user-provided directory. The vulnerability occurs as a bypass for the patch added for CVE-2022-25882.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in Oc
Microsoft
Versions of the package onnx before 1.13.0 are vulnerable to Directory Traversal as the external_data field of the tensor proto can have a path to the file which is outside the model current directory
vendor_msrc·2023-01-10·CVSS 7.5
CVE-2022-25882 [HIGH] CWE-22 Versions of the package onnx before 1.13.0 are vulnerable to Directory Traversal as the external_data field of the tensor proto can have a path to the file which is outside the model current directory
Versions of the package onnx before 1.13.0 are vulnerable to Directory Traversal as the external_data field of the tensor proto can have a path to the file which is outside the model current directory or user-provided directory for example "../../../etc/passwd"
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If im
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://gist.github.com/jnovikov/02a9aff9bf2188033e77bd91ff062856https://github.com/onnx/onnx/blob/96516aecd4c110b0ac57eba08ac236ebf7205728/onnx/checker.cc%23L129https://github.com/onnx/onnx/commit/f369b0e859024095d721f1d1612da5a8fa38988dhttps://github.com/onnx/onnx/issues/3991https://github.com/onnx/onnx/pull/4400https://security.snyk.io/vuln/SNYK-PYTHON-ONNX-2395479https://gist.github.com/jnovikov/02a9aff9bf2188033e77bd91ff062856https://github.com/onnx/onnx/blob/96516aecd4c110b0ac57eba08ac236ebf7205728/onnx/checker.cc%23L129https://github.com/onnx/onnx/commit/f369b0e859024095d721f1d1612da5a8fa38988dhttps://github.com/onnx/onnx/issues/3991https://github.com/onnx/onnx/pull/4400https://security.snyk.io/vuln/SNYK-PYTHON-ONNX-2395479
2023-01-26
Published