huntr.com
https://huntr.com/bounties/644ab868-db6d-4685-ab35-1a897632d2ca CVE-2023-6023
HIGHNuclei
ModelDB Local File Include
Record summary
CVE-2023-6023 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
An attacker can read any file on the filesystem on the server hosting ModelDB through an LFI in the artifact_path URL parameter.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Sep 11, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
modeldbBrowse vertaai / modeldb | VulnCheck | Version data not supplied | |
vertaai/modeldbBrowse vertaai / vertaai/modeldb | CVE List | Through latest | affected |
Nuclei templates
1ProjectDiscoveryHIGHVertaAI ModelDB - Path TraversalCVSS 7.5
The endpoint "/api/v1/artifact/getArtifact?artifact_path=" is vulnerable to path traversal. The main cause of this vulnerability is due to the lack of validation and sanitization of the artifact_path parameter.
Impact
Attackers can potentially exploit this vulnerability to perform a relative path traversal attack, which can lead to unauthorized access to sensitive local files on the server. As an impact it is known to affect confidentiality.
Remediation
Restrict access to the web application
WeaknessesCWE-22CWE-29
Authorsm0ck3d, cookiehanhoan
Template tagscvecve2023lfimodeldbvertaaivkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:vertaai:modeldb:-:*:*:*:*:*:*:*
Shodan: http.favicon.hash:-2097033750
Shodan: http.title:"verta ai"
FOFA: icon_hash=-2097033750
FOFA: title="verta ai"
Google: intitle:"verta ai"
https://huntr.com/bounties/644ab868-db6d-4685-ab35-1a897632d2ca/ https://nvd.nist.gov/vuln/detail/CVE-2023-6023
Source: ProjectDiscovery
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-6023