
Cloud Vulnerability DB
A community-led vulnerabilities database
A vulnerability (CVE-2024-5187) was discovered in the download_model_with_test_data function of the onnx/onnx framework version 1.16.0. The vulnerability allows for arbitrary file overwrite due to inadequate prevention of path traversal attacks in malicious tar files (Huntr Bounty).
The vulnerability stems from inadequate security checks during tar file extraction in the download_model_with_test_data function. The function fails to properly validate paths within tar files, allowing attackers to specify absolute paths that can overwrite system files. This was demonstrated through the ability to overwrite the /home/kali/.ssh/authorized_keys file. The vulnerability has been assigned a CVSS v3.1 score of 8.8 (High) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H (Huntr Bounty).
The vulnerability enables attackers to overwrite any file on the system, which can lead to remote code execution, deletion of system files, personal files, or application files. This significantly impacts both the integrity and availability of the affected system (Huntr Bounty).
The vulnerability can be exploited by crafting a malicious tar file that contains files with absolute paths. When this tar file is processed by the vulnerable function, it allows for arbitrary file overwrite on the system (Huntr Bounty).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."