CVE-2024-6829
CVSS 3.0 Score 9.1 of 10 (critical)
Details
Summary
CVE-2024-6829 is a newly disclosed vulnerability affecting the aimhubio/aim package version 3.19.3. This issue permits an attacker to manipulate the `tarfile.extractall()` function, allowing the extraction of malicious tarfiles to arbitrary locations on the host server. By controlling `repo.path` and `run_hash`, an adversary can bypass directory existence checks and overwrite critical files on the remote tracking server. This vulnerability could potentially be exploited to write arbitrary data and execute further attacks, such as crafting a new SSH key on the target system.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Aim