We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2024-6577

Unclaimed S3 Bucket Usage in pytorch/serve



Description

In the latest version of pytorch/serve, the script 'upload_results_to_s3.sh' references the S3 bucket 'benchmarkai-metrics-prod' without ensuring its ownership or confirming its accessibility. This could lead to potential security vulnerabilities or unauthorized access to the bucket if it is not properly secured or claimed by the appropriate entity. The issue may result in data breaches, exposure of proprietary information, or unauthorized modifications to stored data.

Reserved 2024-07-08 | Published 2025-03-20 | Updated 2025-03-20 | Assigner @huntr_ai


MEDIUM: 6.3CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L

Problem types

CWE-840 Business Logic Errors

Product status

Any version
affected

References

huntr.com/bounties/20917570-8328-428f-bd1d-4fcd71fb2359

cve.org (CVE-2024-6577)

nvd.nist.gov (CVE-2024-6577)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2024-6577

Support options

Helpdesk Chat, Email, Knowledgebase