CVE-2021-43775
Summary
| CVE | CVE-2021-43775 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-11-23 21:15:00 UTC |
| Updated | 2023-11-07 03:39:00 UTC |
| Description | Aim is an open-source, self-hosted machine learning experiment tracking tool. Versions of Aim prior to 3.1.0 are vulnerable to a path traversal attack. By manipulating variables that reference files with “dot-dot-slash (../)” sequences and its variations or by using absolute file paths, it may be possible to access arbitrary files and directories stored on file system including application source code or configuration and critical system files. The vulnerability issue is resolved in Aim v3.1.0. |
Risk And Classification
Problem Types: CWE-22
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Arbitrary file reading vulnerability · Advisory · aimhubio/aim · GitHub | CONFIRM | github.com | |
| Security issue fix for `/static-files/{path}` endpoint by mihran113 · Pull Request #1003 · aimhubio/aim · GitHub | MISC | github.com | |
| Security vulnerabilty · Issue #999 · aimhubio/aim · GitHub | MISC | github.com | |
| aim/views.py at 0b99c6ca08e0ba7e7011453a2f68033e9b1d1bce · aimhubio/aim · GitHub | MISC | github.com | |
| Security issue fix for `/static-files/{path}` endpoint by mihran113 · Pull Request #1003 · aimhubio/aim · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 980005 Python (pip) Security Update for aim (GHSA-8phj-f9w2-cjcc)