CVE-2024-5452
A remote code execution (RCE) vulnerability exists in the lightning-ai/pytorch-lightning library version 2.2.1 due to improper handling of deserialized user input and mismanagement of dunder attributes by the `deepdiff` library.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 26.8%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
A remote code execution (RCE) vulnerability exists in the lightning-ai/pytorch-lightning library version 2.2.1 due to improper handling of deserialized user input and mismanagement of dunder attributes by the `deepdiff` library. The library uses `deepdiff.Delta` objects to modify application state based on frontend actions. However, it is possible to bypass the intended restrictions on modifying dunder attributes, allowing an attacker to construct a serialized delta that passes the deserializer whitelist and contains dunder attributes. When processed, this can be exploited to access other modules, classes, and instances, leading to arbitrary attribute write and total RCE on any self-hosted pytorch-lightning application in its default configuration, as the delta endpoint is enabled by default.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 26.83% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-915, CWE-913
- Affected
- lightningai/pytorch lightning
- Source
- security@huntr.dev
References
- https://github.com/lightning-ai/pytorch-lightning/commit/330af381de88cff17515418a341cbc1f9f127f9a
- https://huntr.com/bounties/486add92-275e-4a7b-92f9-42d84bc759daExploit, Third Party Advisory
- https://huntr.com/bounties/486add92-275e-4a7b-92f9-42d84bc759daExploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.