CVE-2024-27318
HIGHONNX < 1.16.0 - Path Traversal via External Data Field
Title source: llmDescription
Versions of the package onnx before and including 1.15.0 are vulnerable to Directory Traversal as the external_data field of the tensor proto can have a path to the file which is outside the model current directory or user-provided directory. The vulnerability occurs as a bypass for the patch added for CVE-2022-25882.
References (4)
Core 4
Core References
Third Party Advisory
https://lists.fedoraproject.org/archives/list/[email protected]/message/FGTBH5ZYL2LGYHIJDHN2MAUURIR5E7PY/
Scores
CVSS v3
7.5
EPSS
0.0041
EPSS Percentile
61.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-22
Status
published
Products (4)
fedoraproject/fedora
39
fedoraproject/fedora
40
linuxfoundation/onnx
< 1.16.0
pypi/onnx
0 - 1.16.0PyPI
Published
Feb 23, 2024
Tracked Since
Feb 18, 2026