PT-2024-26376 · Unknown · Torchserve
Namannandan
·
Published
2024-07-18
·
Updated
2024-08-07
·
CVE-2024-35199
CVSS v4.0
8.8
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
TorchServe versions prior to 0.11.0
Description
The issue arises from the two gRPC ports 7070 and 7071 not being bound to localhost by default, causing them to be bound to all interfaces when TorchServe is launched. Customers using PyTorch inference Deep Learning Containers through Amazon SageMaker and EKS are not affected.
Recommendations
For versions prior to 0.11.0, upgrade to TorchServe release 0.11.0 to address this issue. As a temporary workaround, consider configuring the gRPC ports to bind to localhost until the upgrade can be applied. Restrict access to the gRPC ports 7070 and 7071 to minimize the risk of exploitation.
Exploit
Fix
Exposure of Resource to Wrong Sphere
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Torchserve