PT-2022-15697 · Nvidia · Nvidia Nemo

Haby0

·

Published

2022-01-08

·

Updated

2022-02-15

·

CVE-2022-22821

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions NVIDIA NeMo versions prior to 1.6.0
Description The issue concerns a Relative Path Traversal vulnerability in the ASR WebApp of NVIDIA NeMo. This vulnerability may lead to the deletion of any directory when admin privileges are available, through the use of the "../" structure. The vulnerability affects cases where the ASR Webapp is used with superuser permissions, and it impacts users who clone the repository and execute the web app.
Recommendations For versions prior to 1.6.0, apply the changes from the commit https://github.com/NVIDIA/NeMo/commit/f7e4ed7e4f7f2fa43765a38c2fafa1b6d1ebd7c0 to patch the vulnerability. As a temporary workaround, consider restricting the use of the ASR Webapp or running it without superuser permissions to minimize the risk of exploitation.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-22821
GHSA-9HG3-HMMF-C3GR
GHSA-RPX7-33J2-XX9X

Affected Products

Nvidia Nemo