CVE-2024-7776
CVSS 3.1 Score 9.1 of 10 (high)
Details
Summary
CVE-2024-7776 is a newly identified vulnerability affecting the `download_model` function in onnx/onnx framework versions prior to 1.16.1. The issue stems from insufficient protection against path traversal assaults in malicious tar files. An assailant can take advantage of this weakness to overwrite files within the user's directory, potentially leading to remote command execution. This vulnerability poses a significant risk for unauthorized system access and data manipulation. Users are strongly advised to update their onnx/onnx framework to a patched version as soon as possible to mitigate this threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.