PT-2023-12827 · Onnx · Onnx

·

CVE-2022-25882

·

Published

2023-01-25

·

Updated

2025-01-22

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions onnx versions prior to 1.13.0
Description The issue allows Directory Traversal, where the external data field of the tensor proto can contain a path to a file outside the model's current directory or user-provided directory. For example, an attacker could use a path like "../../../etc/passwd".
Recommendations For versions prior to 1.13.0, update to version 1.13.0 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive files and directories to minimize the risk of exploitation.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-25854
CVE-2022-25882
GHSA-FFXJ-547X-5J7C
PYSEC-2023-38

Affected Products

Onnx