6.8 MEDIUM
- CVSS version (CVSS): 4.0
- Attack Vector (AV): Local (L)
- Attack Complexity (AC): Low (L)
- Attack Requirement (AT): None (N)
- Privileges Required (PR): None (N)
- User Interaction (UI): Active (A)
- Vulnerable System Impact Confidentiality (VC): None (N)
- Vulnerable System Impact Integrity (VI): High (H)
- Vulnerable System Impact Availability (VA): High (H)
- Subsequent System Impact Confidentiality (SC): None (N)
- Subsequent System Impact Integrity (SI): None (N)
- Subsequent System Impact Availability (SA): None (N)
- Modified Attack Vector (MAV): Local (L)
- Modified Attack Complexity (MAC): Low (L)
- Modified Attack Requirement (MAT): None (N)
- Modified Privileges Required (MPR): None (N)
- Modified User Interaction (MUI): Active (A)
- Modified Vulnerable System Impact Confidentiality (MVC): None (N)
- Modified Vulnerable System Impact Integrity (MVI): High (H)
- Modified Vulnerable System Impact Availability (MVA): High (H)
- Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
- Modified Subsequent System Impact Integrity (MSI): Negligible (N)
- Modified Subsequent System Impact Availability (MSA): Negligible (N)
- Safety (S): Not Defined (X)
- Automatable (AU): Not Defined (X)
- Recovery (R): Not Defined (X)
- Value Density (V): Not Defined (X)
- Vulnerability Response Effort (RE): Not Defined (X)
- Provider Urgency (U): Not Defined (X)
- Confidentiality Req. (CR): Not Defined (X)
- Integrity Req. (IR): Not Defined (X)
- Availability Req. (AR): Not Defined (X)
- Exploit Maturity (E): Not Defined (X)
Activity log
- Created suggestion
ONNX symlink-following and path-traversal arbitrary file write
In ONNX before 1.21.0, the 'save_external_data' function builds the external-data file path from the model's external_data location field and opens it for writing without 'O_NOFOLLOW/O_EXCL', after a non-atomic 'os.path.isfile()' check. A local attacker with write access to the directory where a victim serializes external data can deterministically pre-plant a symlink that is being followed, causing the victim's write to append to any file the victim can write, e.g. ~/.ssh/authorized_keys, cron files, or application configs. Fixed in 1.21.0.
Affected products
- ==1.21.0
- <1.21.0
Matching in nixpkgs
pkgs.onnx
Open Neural Network Exchange
pkgs.onnxruntime
Cross-platform, high performance scoring engine for ML models
pkgs.sherpa-onnx
Speech-to-text, text-to-speech, and speaker recognition using next-gen Kaldi with onnxruntime
pkgs.pkgsRocm.onnxruntime
Cross-platform, high performance scoring engine for ML models
pkgs.pkgsRocm.sherpa-onnx
Speech-to-text, text-to-speech, and speaker recognition using next-gen Kaldi with onnxruntime
pkgs.python313Packages.onnx
Open Neural Network Exchange
pkgs.python314Packages.onnx
Open Neural Network Exchange
pkgs.python313Packages.onnx-ir
Efficient in-memory representation for ONNX, in Python
pkgs.python313Packages.tf2onnx
Convert TensorFlow, Keras, Tensorflow.js and Tflite models to ONNX
pkgs.python314Packages.onnx-ir
Efficient in-memory representation for ONNX, in Python
pkgs.python313Packages.onnx-asr
Lightweight Automatic Speech Recognition using ONNX models
pkgs.python313Packages.onnxslim
Toolkit to Help Optimize Onnx Model
pkgs.python313Packages.skl2onnx
Convert scikit-learn models to ONNX
pkgs.python314Packages.onnx-asr
Lightweight Automatic Speech Recognition using ONNX models
pkgs.python314Packages.onnxslim
Toolkit to Help Optimize Onnx Model
pkgs.python314Packages.skl2onnx
Convert scikit-learn models to ONNX
pkgs.python313Packages.onnxscript
Naturally author ONNX functions and models using a subset of Python
pkgs.python314Packages.onnxscript
Naturally author ONNX functions and models using a subset of Python
pkgs.python313Packages.onnxmltools
ONNXMLTools enables conversion of models to ONNX
pkgs.python313Packages.onnxruntime
Cross-platform, high performance scoring engine for ML models
pkgs.python313Packages.sherpa-onnx
Python bindings for sherpa-onnx speech recognition
pkgs.python314Packages.onnxmltools
ONNXMLTools enables conversion of models to ONNX
pkgs.python314Packages.onnxruntime
Cross-platform, high performance scoring engine for ML models
pkgs.python314Packages.sherpa-onnx
Python bindings for sherpa-onnx speech recognition
pkgs.python313Packages.optimum-onnx
Export your model to ONNX and run inference with ONNX Runtime
pkgs.python314Packages.optimum-onnx
Export your model to ONNX and run inference with ONNX Runtime
pkgs.pkgsRocm.python3Packages.onnx-ir
Efficient in-memory representation for ONNX, in Python
pkgs.pkgsRocm.python3Packages.tf2onnx
None
pkgs.pkgsRocm.python3Packages.onnx-asr
Lightweight Automatic Speech Recognition using ONNX models
pkgs.pkgsRocm.python3Packages.onnxscript
Naturally author ONNX functions and models using a subset of Python
pkgs.python313Packages.onnxruntime-tools
Transformers Model Optimization Tool of ONNXRuntime
pkgs.python314Packages.onnxruntime-tools
Transformers Model Optimization Tool of ONNXRuntime
pkgs.pkgsRocm.python3Packages.onnxruntime
Cross-platform, high performance scoring engine for ML models
pkgs.pkgsRocm.python3Packages.sherpa-onnx
Python bindings for sherpa-onnx speech recognition
pkgs.pkgsRocm.python3Packages.optimum-onnx
Export your model to ONNX and run inference with ONNX Runtime
pkgs.python313Packages.onnxconverter-common
ONNX Converter and Optimization Tools
pkgs.python313Packages.rapidocr-onnxruntime
Cross platform OCR Library based on OnnxRuntime
pkgs.python314Packages.onnxconverter-common
ONNX Converter and Optimization Tools
pkgs.python314Packages.rapidocr-onnxruntime
Cross platform OCR Library based on OnnxRuntime
Package maintainers
-
@acairncross Aiken Cairncross <acairncross@gmail.com>
-
@ConnorBaker Connor Baker <ConnorBaker01@gmail.com>
-
@puffnfresh Brian McKenna <brian@brianmckenna.org>
-
@ck3d Christian Kögler <ck3d@gmx.de>
-
@jaredmontoya Jared Montoya
-
@GaetanLepage Gaetan Lepage <gaetan@glepage.com>
-
@wrvsrx wrvsrx <wrvsrx@outlook.com>
-
@happysalada Raphael Megzari <raphael@megzari.com>