CVE-2024-6577

CVSS 3.0 Score 6.3 of 10 (medium)

Details

Published Mar 20, 2025
CWE ID 840

Summary

CVE-2024-6577 is a vulnerability affecting the latest version of pytorch/serve. The script 'upload_results_to_s3.sh' in this software references an Amazon S3 bucket ('benchmarkai-metrics-prod') without proper authentication checks. This could lead to unauthorized access or data breaches if the bucket is not adequately secured. Potential consequences include exposure of proprietary information and unauthorized modifications to stored data. It is crucial for users to verify their access to this bucket and ensure its security to mitigate the risks associated with this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share