Unauthorized S3 Bucket Reference in PyTorch Serve by Meta
CVE-2024-6577
6.3MEDIUM
What is CVE-2024-6577?
The presence of an improper access control vulnerability in PyTorch Serve involves the script 'upload_results_to_s3.sh', which references an S3 bucket without validating ownership or accessibility. This oversight poses significant security risks, such as unauthorized access, data breaches, potential modification of sensitive data, or exposure of proprietary information. It is crucial for stakeholders to ensure proper security measures are in place to protect S3 bucket resources and mitigate these vulnerabilities.
Affected Version(s)
pytorch/serve <= unspecified