CVE-2024-35199
Last modified
CVE-2024-35199 is a high-severity vulnerability rated 8.2/10 on the CVSS scale. TorchServe is a flexible and easy-to-use tool for serving and scaling PyTorch models in production. In affected versions the two gRPC ports 7070 and 7071, are not bound to [localhost](http://localhost/) by default, so when TorchServe is launched, these two interfaces are bound to all interfaces. EPSS estimates a 0.63% chance of exploitation in the next 30 days.
Description
TorchServe is a flexible and easy-to-use tool for serving and scaling PyTorch models in production. In affected versions the two gRPC ports 7070 and 7071, are not bound to [localhost](http://localhost/) by default, so when TorchServe is launched, these two interfaces are bound to all interfaces. Customers using PyTorch inference Deep Learning Containers (DLC) through Amazon SageMaker and EKS are not affected. This issue in TorchServe has been fixed in PR #3083. TorchServe release 0.11.0 includes the fix to address this vulnerability. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Pytorch | Torchserve | >= 0.3.0, < 0.11.0 |
References
- https://github.com/pytorch/serve/security/advisories/GHSA-hhpg-v63p-wp7wPatch, Third Party Advisory
- https://github.com/pytorch/serve/security/advisories/GHSA-hhpg-v63p-wp7wPatch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-35199?
How severe is CVE-2024-35199?
How do I fix CVE-2024-35199?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-35192Trivy is a security scanner. Prior to 0.51.2, if a malicious…5.5
- CVE-2024-35194Minder is a software supply chain security platform. Prior t…5.3
- CVE-2024-35195Requests is a HTTP library. Prior to 2.32.0, when making req…5.6
- CVE-2024-35196Sentry is a developer-first error tracking and performance m…2
- CVE-2024-35197gitoxide is a pure Rust implementation of Git. On Windows, f…5.4
- CVE-2024-35198TorchServe is a flexible and easy-to-use tool for serving an…9.8
- CVE-2024-3520The Country State City Dropdown CF7 plugin for WordPress is …4.3
- CVE-2024-35200When NGINX Plus or NGINX OSS are configured to use the HTTP/…5.3
- CVE-2024-35201Incorrect default permissions in the Intel(R) SDP Tool for W…7.8
- CVE-2024-35202Bitcoin Core before 25.0 allows remote attackers to cause a …7.5
- CVE-2024-35203Mahara before 22.10.6, 23.04.6, and 24.04.1 allows cross-sit…6.1
- CVE-2024-35204Veritas System Recovery before 23.3_Hotfix has incorrect per…8.4
Are you affected by CVE-2024-35199?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
