CVE-2024-5980
pytorch-lightning vulnerable to Arbitrary File Write via /v1/runs API endpoint
9.1
CRITICAL
CVSS 3.1
EPSS 10.7%
Description
A vulnerability in the /v1/runs API endpoint of lightning-ai/pytorch-lightning v2.2.4 allows attackers to exploit path traversal when extracting tar.gz files. When the LightningApp is running with the plugin_server, attackers can deploy malicious tar.gz plugins that embed arbitrary files with path traversal vulnerabilities. This can result in arbitrary files being written to any directory in the victim's local file system, potentially leading to remote code execution.
How to fix CVE-2024-5980
To remediate CVE-2024-5980, upgrade the affected package to a fixed version below.
- —upgrade to 2.3.3 or later
Is CVE-2024-5980 being exploited?
Moderate — EPSS is 10.7%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- from 0, < 2.3.3
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.1 | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H |