CVE-2024-8019
ADVISORY - githubSummary
In lightning-ai/pytorch-lightning version 2.3.2, a vulnerability exists in the LightningApp when running on a Windows host. The vulnerability occurs at the /api/v1/upload_file/ endpoint, allowing an attacker to write or overwrite arbitrary files by providing a crafted filename. This can lead to potential remote code execution (RCE) by overwriting critical files or placing malicious files in sensitive locations.
EPSS Score: 0.01113 (0.782)
Common Weakness Enumeration (CWE)
ADVISORY - nist
Unrestricted Upload of File with Dangerous Type
ADVISORY - github
Unrestricted Upload of File with Dangerous Type
Sign in to Docker Scout
See which of your images are affected by this CVE and how to fix them by signing into Docker Scout.
Sign in