PT-2024-5048 · Unknown · Deepjavalibrary

Tosterberg

·

Published

2024-05-16

·

Updated

2024-07-08

·

CVE-2024-37902

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: DeepJavaLibrary(DJL) versions 0.1.0 through 0.27.0
Description: The issue is related to the incorrect restriction of the directory path name with limited access. This can allow a remote attacker to overwrite system files. The estimated number of potentially affected devices is not specified. There is no information about real-world incidents where this issue was exploited.
Recommendations: For DeepJavaLibrary(DJL) versions 0.1.0 through 0.27.0, users are advised to upgrade to version 0.28.0 or apply the patch in DJL Large Model Inference containers version 0.27.0. As a temporary workaround, consider restricting the use of absolute path archived artifacts to prevent them from inserting archived files directly into the system.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

BDU:2024-05575
CVE-2024-37902
GHSA-W877-JFW7-46RJ

Affected Products

Deepjavalibrary