peter bassill · operator
$ cve CVE-2024-6396 JSON

CVE-2024-6396

9.8
CRITICAL · CVSS 3.0 · EPSS 53.1% (pctl 99)

Patch early

EPSS 53.1% — above the 10% action threshold.

Description

A vulnerability in the `_backup_run` function in aimhubio/aim version 3.19.3 allows remote attackers to overwrite any file on the host server and exfiltrate arbitrary data. The vulnerability arises due to improper handling of the `run_hash` and `repo.path` parameters, which can be manipulated to create and write to arbitrary file paths. This can lead to denial of service by overwriting critical system files, loss of private data, and potential remote code execution.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS53.11% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-29
On CISA KEVno
Public exploitnone known
Published2024-07-12
Last modified2026-06-17

Affected (1)

VendorProduct
aimstackaim

References

→ the Explorer  ·  watch your stack  ·  NVD