PT-2025-12162 · Aimhubio · Aim
Published
2025-03-20
·
Updated
2025-03-21
·
CVE-2024-6483
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
aimhubio/aim version 3.19.3
Description
A vulnerability in the "runs/delete-batch" endpoint allows for arbitrary file or directory deletion through path traversal. The endpoint does not mitigate path traversal when handling user-specified
run-names, which are used to specify log/metadata files for deletion. This can be exploited to delete arbitrary files or directories, potentially causing denial of service or data loss.Recommendations
For aimhubio/aim version 3.19.3, consider disabling the
runs/delete-batch endpoint until a patch is available to prevent arbitrary file or directory deletion. Restrict access to the endpoint to minimize the risk of exploitation. Avoid using user-specified run-names in the affected endpoint until the issue is resolved.Exploit
Fix
Relative Path Traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Aim