CVE-2022-25882
Published on: Not Yet Published
Last Modified on: 02/02/2023 06:20:00 PM UTC
Certain versions of Onnx from Linuxfoundation contain the following vulnerability:
Versions of the package onnx before 1.13.0 are vulnerable to Directory Traversal as the external_data field of the tensor proto can have a path to the file which is outside the model current directory or user-provided directory, for example "../../../etc/passwd"
- CVE-2022-25882 has been assigned by
[email protected] to track the vulnerability - currently rated as HIGH severity.
CVSS3 Score: 7.5 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | NONE | NONE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Do not allow to read tensor's external_data outside the model directo… · onnx/[email protected] · GitHub | github.com text/html |
![]() |
Directory Traversal in onnx | CVE-2022-25882 | Snyk | security.snyk.io text/html |
![]() |
The onnx runtime allow to load the external_data from the file outside the folder · Issue #3991 · onnx/onnx · GitHub | github.com text/html |
![]() |
Do not allow to read tensor's external_data outside the model directory by jnovikov · Pull Request #4400 · onnx/onnx · GitHub | github.com text/html |
![]() |
Onnx runtime poc · GitHub | gist.github.com text/html |
![]() |
onnx/checker.cc at 96516aecd4c110b0ac57eba08ac236ebf7205728 · onnx/onnx · GitHub | github.com text/html |
![]() |
There are currently no QIDs associated with this CVE
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Linuxfoundation | Onnx | All | All | All | All |
- cpe:2.3:a:linuxfoundation:onnx:*:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2022-25882 : Versions of the package onnx before 1.13.0 are vulnerable to Directory Traversal as the external_d… twitter.com/i/web/status/1… | 2023-01-26 21:19:25 |