Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:39063
HistoryJan 31, 2023 - 3:43 a.m.

Directory Traversal

2023-01-3103:43:00
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12
onnx
vulnerability
check_tensor
checker.cc
external_data
unvalidated path
directory traversal

EPSS

0.002

Percentile

59.9%

onnx is vulnerable to Directory Traversal. The vulnerability exists in the check_tensor function of checker.cc as the external_data field of the tensor proto may have an unvalidated path to a file which is outside the current model directory or a user-provided directory.