ModelDB是VertaAI开源的一个用于机器学习模型版本控制、元数据和实验管理的开源系统。 ModelDB 存在安全漏洞,该漏洞源于artifact_path URL参数存在远程文件包含(LFI)漏洞。攻击者可利用该漏洞读取ModelDB服务器文件系统上的任何文件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| vertaai | vertaai/modeldb | unspecified ~ latest | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | The endpoint "/api/v1/artifact/getArtifact?artifact_path=" is vulnerable to path traversal. The main cause of this vulnerability is due to the lack of validation and sanitization of the artifact_path parameter. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2023/CVE-2023-6023.yaml | POC Details |
No public POC found.
Login to generate AI POCNo comments yet