CVE-2024-8238
CVSS 3.0 Score 5.9 of 10 (medium)
Details
Summary
CVE-2024-8238 is a vulnerability affecting version 3.22.0 of aimhubio/aim. The issue stems from the outdated safer_getattr() function in RestrictedPython used by the AimQL query language. This specific version fails to safeguard against the str.format_map() method, allowing attackers to potentially leak server-side secrets or gain unrestricted code execution. Attackers can abuse str.format_map() to read arbitrary attributes of Python objects, including sensitive variables like os.environ. If an attacker manages to write files to a known location on the Aim server, they can exploit this vulnerability to load a malicious .dll/.so file into the Python interpreter, resulting in unrestricted code execution.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Aim