VDB
BDU%3A2023-06445
BDU%3A2023-06445
PUBLISHED
CVSS 6.400000095367432 MEDIUM
Уязвимость конфигурации allowed_urls инструмента для обслуживания и масштабирования моделей машинного обучения PyTorch TorchServe, позволяющая нарушителю осуществить SSRF-атаку
Risk Scores
CVSS 2.0
6.400000095367432
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Сообщество свободного программного обеспечения | TorchServe |
Timeline
- Oct 10, 2023 CVE Published
- Sep 13, 2024 CVE Updated
References
- https://github.com/pytorch/serve/releases/tag/v0.8.2 url
- https://github.com/pytorch/serve/security/advisories/GHSA-8fxr-qfr9-p34w url
- https://vuldb.com/ru/?id.240857 url
- http://packetstormsecurity.com/files/175095/PyTorch-Model-Server-Registration-Deserialization-Remote-Code-Execution.html url
- https://github.com/pytorch/serve/pull/2534 advisory