mirror of
https://github.com/fkie-cad/nvd-json-data-feeds.git
synced 2025-05-29 01:31:20 +00:00
44 lines
1.3 KiB
JSON
44 lines
1.3 KiB
JSON
{
|
|
"id": "CVE-2024-48063",
|
|
"sourceIdentifier": "cve@mitre.org",
|
|
"published": "2024-10-29T21:15:04.080",
|
|
"lastModified": "2025-01-09T18:15:29.013",
|
|
"vulnStatus": "Awaiting Analysis",
|
|
"cveTags": [
|
|
{
|
|
"sourceIdentifier": "cve@mitre.org",
|
|
"tags": [
|
|
"disputed"
|
|
]
|
|
}
|
|
],
|
|
"descriptions": [
|
|
{
|
|
"lang": "en",
|
|
"value": "In PyTorch <=2.4.1, the RemoteModule has Deserialization RCE. NOTE: this is disputed by multiple parties because this is intended behavior in PyTorch distributed computing."
|
|
},
|
|
{
|
|
"lang": "es",
|
|
"value": " En PyTorch <=2.4.1, RemoteModule tiene RCE de deserializaci\u00f3n."
|
|
}
|
|
],
|
|
"metrics": {},
|
|
"references": [
|
|
{
|
|
"url": "https://gist.github.com/hexian2001/c046c066895a963ecc0a2cf9e1180065",
|
|
"source": "cve@mitre.org"
|
|
},
|
|
{
|
|
"url": "https://github.com/pytorch/pytorch/issues/129228",
|
|
"source": "cve@mitre.org"
|
|
},
|
|
{
|
|
"url": "https://github.com/pytorch/pytorch/security/policy#using-distributed-features",
|
|
"source": "cve@mitre.org"
|
|
},
|
|
{
|
|
"url": "https://rumbling-slice-eb0.notion.site/Distributed-RPC-Framework-RemoteModule-has-Deserialization-RCE-in-pytorch-pytorch-111e3cda9e8c8021a7d3cbc61ee1a20c",
|
|
"source": "cve@mitre.org"
|
|
}
|
|
]
|
|
} |