VDB
CVE-2024-5187
CVE-2024-5187
PUBLISHED
CVSS 8.800000190734863 HIGH
onnx allows Arbitrary File Overwrite in download_model_with_test_data
EPSS 1.18% · 66.2th percentile
Risk Scores
CVSS 3.0
8.800000190734863
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
1.18%
66.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| onnx | onnx/onnx | unspecified |
| linuxfoundation | onnx | 1.16.0 |
| linuxfoundation | onnx | 1.16.0 |
| PyPI | onnx | 0 |
Timeline
- Jun 6, 2024 CVE Published
- Jun 7, 2024 EPSS Score
- Jul 1, 2024 EPSS Score
- Aug 17, 2024 EPSS Score
- Sep 9, 2024 EPSS Score
- Oct 3, 2024 EPSS Score
- Oct 5, 2024 Coalition ESS Score
- Oct 23, 2024 Coalition ESS Score
- Nov 19, 2024 EPSS Score
- Dec 13, 2024 EPSS Score
- Jan 6, 2025 EPSS Score
- Feb 22, 2025 EPSS Score
References
- https://huntr.com/bounties/50235ebd-3410-4ada-b064-1a648e11237e url
- https://nvd.nist.gov/vuln/detail/CVE-2024-5187 advisory
- https://github.com/onnx/onnx package
- https://github.com/onnx/onnx/issues/6215 discussion
- https://github.com/onnx/onnx/pull/6145 fix
- https://github.com/onnx/onnx/pull/6222 fix
- https://github.com/onnx/onnx/commit/1b70f9b673259360b6a2339c4bd97db9ea6e552f fix
- https://github.com/onnx/onnx/commit/3fc3845edb048df559aa2a839e39e95503a0ee34 fix
- https://github.com/onnx/onnx/releases/tag/v1.16.2 fix