CVE-2024-8019 is a critical vulnerability affecting Lightning AI's PyTorch Lightning version 2.3.2 when running on Windows hosts. An unauthenticated attacker can exploit the /api/v1/upload_file/ endpoint to write or overwrite arbitrary files by manipulating the filename, leading to potential remote code execution (RCE). With a CVSS score of 9.1 (CRITICAL), this vulnerability has a low attack complexity and requires no user interaction, allowing for complete compromise of integrity and availability. While no public exploits, Metasploit modules, or community discussions are currently identified, its high FAUCET Risk Score of 85/100 indicates significant potential for impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.3.2CPE matchmatch criteria | cpe:2.3:a:lightningai:pytorch_lightning:2.3.2:*:*:*:*:python:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.