Developer Tools & Libraries

Remote Code Execution

Code Injection in pytorch-lightning prior to 1.6.0

Code Execution in the context of the program can be achieved in pytorch-lightning prior to v1.6.0 It is possible to execute OS commands or snippets of python code in the context of the program by…

7.3
/ 10
High
CVSS v3.0
ADVISORY ID
PS52
PUBLISHED
2022-10-05
CVE IDs
CVE-2022-0845
VENDORS
PyTorch Lightning
PUBLIC EXPLOIT
PoC public
CWE
CWE-94
PRODUCT
pytorch-lightning
CVSS VECTOR
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L
Abstract blurred background with dark tones and smooth gradient waves of blue, purple, and orange hues.
Summary

Overview

Code Execution in the context of the program can be achieved in pytorch-lightning prior to v1.6.0

It is possible to execute OS commands or snippets of python code in the context of the program by using the PL_TRAINER_GPUS environment variable. Setting the environment variable with a malicious payload would lead to the execution of the payload thereby enabling an attacker to run their own commands in the same context as the pytorch-lightning program.

Vulnerability details

Vulnerability details

CVE-2022-0845
CWE-94
High | 7.3

Code Execution in the context of the program can be achieved in pytorch-lightning prior to v1.6.0 It is possible to execute OS commands or snippets of python code in the context of the program by using the PL_TRAINER_GPUS environment variable.

Auth:
None (local access, user interaction required)
Impact:
Sensitive data disclosure, arbitrary data or code modification, partial service degradation
DISCLOSURE

Disclosure timeline

2022-03-03 Reported On

2022-03-04 Made Public On

2022-03-06 Fixed On

Credits

Debjeet Banerjee