CVE-2021-43775
Last modified
CVE-2021-43775 is a high-severity vulnerability rated 8.6/10 on the CVSS scale. Aim is an open-source, self-hosted machine learning experiment tracking tool. Versions of Aim prior to 3.1.0 are vulnerable to a path traversal attack. EPSS estimates a 1.85% chance of exploitation in the next 30 days.
Description
Aim is an open-source, self-hosted machine learning experiment tracking tool. Versions of Aim prior to 3.1.0 are vulnerable to a path traversal attack. By manipulating variables that reference files with “dot-dot-slash (../)” sequences and its variations or by using absolute file paths, it may be possible to access arbitrary files and directories stored on file system including application source code or configuration and critical system files. The vulnerability issue is resolved in Aim v3.1.0.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Aimstack | Aim | < 3.1.0 |
References
- https://github.com/aimhubio/aim/issues/999Issue Tracking, Third Party Advisory
- https://github.com/aimhubio/aim/pull/1003Patch, Third Party Advisory
- https://github.com/aimhubio/aim/security/advisories/GHSA-8phj-f9w2-cjccExploit, Third Party Advisory
- https://github.com/aimhubio/aim/issues/999Issue Tracking, Third Party Advisory
- https://github.com/aimhubio/aim/pull/1003Patch, Third Party Advisory
- https://github.com/aimhubio/aim/security/advisories/GHSA-8phj-f9w2-cjccExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-43775?
How severe is CVE-2021-43775?
How do I fix CVE-2021-43775?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-43767Odyssey passes to client unencrypted bytes from man-in-the-m…5.9
- CVE-2021-43768In Malwarebytes For Teams v.1.0.990 and before and fixed in …5.3
- CVE-2021-4377The Doneren met Mollie plugin for WordPress is vulnerable to…6.5
- CVE-2021-43771Trend Micro Antivirus for Mac 2021 v11 (Consumer) is vulnera…7.8
- CVE-2021-43772Trend Micro Security 2021 v17.0 (Consumer) contains a vulner…5.5
- CVE-2021-43774A risky-algorithm issue was discovered on Fujifilm DocuCentr…4.9
- CVE-2021-43776Backstage is an open platform for building developer portals…6.1
- CVE-2021-43777Redash is a package for data visualization and sharing. In R…6.1
- CVE-2021-43778Barcode is a GLPI plugin for printing barcodes and QR codes.…7.5
- CVE-2021-43779GLPI is an open source IT Asset Management, issue tracking s…9.9
- CVE-2021-4378The WP Quick FrontEnd Editor plugin for WordPress is vulnera…5.4
- CVE-2021-43780Redash is a package for data visualization and sharing. In v…8.8
Are you affected by CVE-2021-43775?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
