CVE-2024-1961

HIGH

vertaai/modeldb < latest - Path Traversal and Remote Code Execution via Artifact Path Parameter

Title source: llm
STIX 2.1

Description

vertaai/modeldb is vulnerable to a path traversal attack due to improper sanitization of user-supplied file paths in its file upload functionality. Attackers can exploit this vulnerability to write arbitrary files anywhere in the file system by manipulating the 'artifact_path' parameter. This flaw can lead to Remote Code Execution (RCE) by overwriting critical files, such as the application's configuration file, especially when the application is run outside of Docker. The vulnerability is present in the NFSController.java and NFSService.java components of the application.

References (1)

Core 1
Core References

Scores

CVSS v3 8.8
EPSS 0.0103
EPSS Percentile 59.4%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-22
Status published
Products (1)
vertaai/vertaai/modeldb unspecified - latest
Published Apr 16, 2024
Tracked Since Feb 18, 2026