7.5 HIGH
- CVSS version: 3.1
- Attack vector (AV): NETWORK
- Attack complexity (AC): LOW
- Privileges required (PR): NONE
- User interaction (UI): NONE
- Scope (S): UNCHANGED
- Confidentiality impact (C): HIGH
- Integrity impact (I): NONE
- Availability impact (A): NONE
Versions of the package onnx before and including 1.15.0 are …
Versions of the package onnx before and including 1.15.0 are vulnerable to Directory Traversal as the external_data field of the tensor proto can have a path to the file which is outside the model current directory or user-provided directory. The vulnerability occurs as a bypass for the patch added for CVE-2022-25882.
References
-
https://security.snyk.io/vuln/SNYK-PYTHON-ONNX-2395479 x_transferred
Affected products
- =<1.15.0
Matching in nixpkgs
pkgs.onnxruntime
Cross-platform, high performance scoring engine for ML models
pkgs.python311Packages.onnx
Open Neural Network Exchange
pkgs.python312Packages.onnx
Open Neural Network Exchange
pkgs.python311Packages.skl2onnx
Convert scikit-learn models to ONNX
-
nixos-unstable skl2onnx-1.17.0
- nixpkgs-unstable skl2onnx-1.17.0
- nixos-unstable-small skl2onnx-1.17.0
pkgs.python312Packages.skl2onnx
Convert scikit-learn models to ONNX
-
nixos-unstable skl2onnx-1.17.0
- nixpkgs-unstable skl2onnx-1.17.0
- nixos-unstable-small skl2onnx-1.17.0
pkgs.python311Packages.onnxmltools
ONNXMLTools enables conversion of models to ONNX
pkgs.python311Packages.onnxruntime
Cross-platform, high performance scoring engine for ML models
pkgs.python312Packages.onnxmltools
ONNXMLTools enables conversion of models to ONNX
pkgs.python312Packages.onnxruntime
Cross-platform, high performance scoring engine for ML models
pkgs.python311Packages.onnxruntime-tools
Transformers Model Optimization Tool of ONNXRuntime
pkgs.python312Packages.onnxruntime-tools
Transformers Model Optimization Tool of ONNXRuntime
pkgs.python311Packages.onnxconverter-common
ONNX Converter and Optimization Tools
pkgs.python311Packages.rapidocr-onnxruntime
Cross platform OCR Library based on OnnxRuntime
pkgs.python312Packages.onnxconverter-common
ONNX Converter and Optimization Tools
pkgs.python312Packages.rapidocr-onnxruntime
Cross platform OCR Library based on OnnxRuntime
Package maintainers
-
@ck3d Christian Kögler <ck3d@gmx.de>
-
@cbourjau Christian Bourjau <christianb@posteo.de>
-
@puffnfresh Brian McKenna <brian@brianmckenna.org>
-
@acairncross Aiken Cairncross <acairncross@gmail.com>
-
@happysalada Raphael Megzari <raphael@megzari.com>
-
@pluiedev Leah Amelia Chen <hi@pluie.me>