Security Advisory

CVE-2024-6577

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-03-20 10:10:36
Last updated 2025-03-20 18:19:07
Assigner @huntr_ai
State PUBLISHED

Description

In the latest version of pytorch/serve, the script upload_results_to_s3.sh references the S3 bucket benchmarkai-metrics-prod without ensuring its ownership or confirming its accessibility. This could lead to potential security vulnerabilities or unauthorized access to the bucket if it is not properly secured or claimed by the appropriate entity. The issue may result in data breaches, exposure of proprietary information, or unauthorized modifications to stored data.