CVE-2024-27318
published 2024-02-23CVE-2024-27318: Versions of the package onnx before and including 1.15.0 are vulnerable to Directory Traversal as the external_data field of the tensor proto can have a path…
PriorityP343high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
1.19%
64.8th percentile
Versions of the package onnx before and including 1.15.0 are vulnerable to Directory Traversal as the external_data field of the tensor proto can have a path to the file which is outside the model current directory or user-provided directory. The vulnerability occurs as a bypass for the patch added for CVE-2022-25882.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| linuxfoundation | onnx | < 1.16.0 | 1.16.0 |
| msrc | azl3_pytorch_2.2.2-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_pytorch_2.2.2-7_on_azure_linux_3.0 | — | — |
| msrc | azure_linux_3.0_arm | — | — |
| msrc | azure_linux_3.0_x64 | — | — |
| msrc | cbl2_pytorch_2.0.0-6_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_pytorch_2.0.0-8_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| onnx | onnx | < 66b7fb630903fdcf3e83b6b6d56d82e904264a20 | 66b7fb630903fdcf3e83b6b6d56d82e904264a20 |
| onnx | onnx | >= 0 < 66b7fb630903fdcf3e83b6b6d56d82e904264a20 | 66b7fb630903fdcf3e83b6b6d56d82e904264a20 |
| onnx | onnx | >= 0 < 1.16.0 | 1.16.0 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
ghsa7.5HIGH
osv7.5HIGH
vendor_msrc7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2024-27318: Versions of the package onnx before and including 1
osv·2024-02-23·CVSS 7.5
CVE-2024-27318 [HIGH] CVE-2024-27318: Versions of the package onnx before and including 1
Versions of the package onnx before and including 1.15.0 are vulnerable to Directory Traversal as the external_data field of the tensor proto can have a path to the file which is outside the model current directory or user-provided directory. The vulnerability occurs as a bypass for the patch added for CVE-2022-25882.
GHSA
Onnx Directory Traversal vulnerability
ghsa·2024-02-23·CVSS 7.5
CVE-2024-27318 [HIGH] CWE-22 Onnx Directory Traversal vulnerability
Onnx Directory Traversal vulnerability
Versions of the package onnx before and including 1.15.0 are vulnerable to Directory Traversal as the external_data field of the tensor proto can have a path to the file which is outside the model current directory or user-provided directory. The vulnerability occurs as a bypass for the patch added for CVE-2022-25882.
OSV
Onnx Directory Traversal vulnerability
osv·2024-02-23·CVSS 7.5
CVE-2024-27318 [HIGH] Onnx Directory Traversal vulnerability
Onnx Directory Traversal vulnerability
Versions of the package onnx before and including 1.15.0 are vulnerable to Directory Traversal as the external_data field of the tensor proto can have a path to the file which is outside the model current directory or user-provided directory. The vulnerability occurs as a bypass for the patch added for CVE-2022-25882.
Microsoft
Versions of the package onnx before and including 1.15.0 are vulnerable to Directory Traversal as the external_data field of the tensor proto can have a path to the file which is outside the model cur
vendor_msrc·2024-02-13·CVSS 7.5
CVE-2024-27318 [HIGH] CWE-22 Versions of the package onnx before and including 1.15.0 are vulnerable to Directory Traversal as the external_data field of the tensor proto can have a path to the file which is outside the model cur
Versions of the package onnx before and including 1.15.0 are vulnerable to Directory Traversal as the external_data field of the tensor proto can have a path to the file which is outside the model current directory or user-provided directory. The vulnerability occurs as a bypass for the patch added for CVE-2022-25882.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in Oc
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/onnx/onnx/commit/66b7fb630903fdcf3e83b6b6d56d82e904264a20https://lists.fedoraproject.org/archives/list/[email protected]/message/FGTBH5ZYL2LGYHIJDHN2MAUURIR5E7PY/https://lists.fedoraproject.org/archives/list/[email protected]/message/TFJJID2IZDOLFDMWVYTBDI75ZJQC6JOL/https://security.snyk.io/vuln/SNYK-PYTHON-ONNX-2395479https://github.com/onnx/onnx/commit/66b7fb630903fdcf3e83b6b6d56d82e904264a20https://lists.fedoraproject.org/archives/list/[email protected]/message/FGTBH5ZYL2LGYHIJDHN2MAUURIR5E7PY/https://lists.fedoraproject.org/archives/list/[email protected]/message/TFJJID2IZDOLFDMWVYTBDI75ZJQC6JOL/https://security.snyk.io/vuln/SNYK-PYTHON-ONNX-2395479
2024-02-23
Published