Lucene search

K
cveGitHub_MCVE-2024-34073
HistoryMay 03, 2024 - 11:15 a.m.

CVE-2024-34073

2024-05-0311:15:22
CWE-78
GitHub_M
web.nvd.nist.gov
36
sagemaker-python-sdk
command injection
cve-2024-34073
os vulnerability
amazon sagemaker
remote code execution
denial of service
confidentiality
integrity
upgrade
requirements_path
capture_dependencies function

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

8

Confidence

High

EPSS

0.001

Percentile

16.3%

sagemaker-python-sdk is a library for training and deploying machine learning models on Amazon SageMaker. In affected versions the capture_dependencies function in sagemaker.serve.save_retrive.version_1_0_0.save.utils module allows for potentially unsafe Operating System (OS) Command Injection if inappropriate command is passed as the “requirements_path” parameter. This consequently may allow an unprivileged third party to cause remote code execution, denial of service, affecting both confidentiality and integrity. This issue has been addressed in version 2.214.3. Users are advised to upgrade. Users unable to upgrade should not override the “requirements_path” parameter of capture_dependencies function in sagemaker.serve.save_retrive.version_1_0_0.save.utils, and instead use the default value.

Affected configurations

Vulners
Vulnrichment
Node
awssagemaker_python_sdkRange<2.214.3
VendorProductVersionCPE
awssagemaker_python_sdk*cpe:2.3:a:aws:sagemaker_python_sdk:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "aws",
    "product": "sagemaker-python-sdk",
    "versions": [
      {
        "version": "< 2.214.3",
        "status": "affected"
      }
    ]
  }
]

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

8

Confidence

High

EPSS

0.001

Percentile

16.3%