Junglewise Threat Intelligence

CVE-2024-5187: ONNX path traversal in download_model_with_test_data

CVE-2024-5187 · Severity: high · CVSS 8.8 · Published 2024-06-06

Technologies: onnx (PyPI). Vendors: PyPI.

Executive brief

ONNX is an open-source format for artificial intelligence models. A security flaw in its model download utility allows a malicious model file to overwrite critical system files when it is downloaded and extracted. This could allow an attacker to gain unauthorized access to the system, delete important data, or disrupt operations.

Technical details

A path traversal vulnerability (CWE-22) exists in the `download_model_with_test_data` function of the ONNX framework. The root cause is the lack of validation for file paths contained within tar archives during extraction. An attacker can craft a malicious tar file containing absolute paths or parent directory references (e.g., `../../`) to overwrite arbitrary files on the host system. This can be leveraged for remote code execution (e.g., by overwriting `.ssh/authorized_keys`) or denial of service. Exploitation requires a user to download a malicious model using the affected function. The issue is resolved in version 1.16.2.

Affected products

  • onnx onnx < 1.16.2

Timeline

  • 2024-06-06: disclosed
  • 2024-06-06: advisory
  • 2024-06-06: patched: Version 1.16.2 released

References

Related threats