CVE-2022-0845: Code Injection in pytorchlightning/pytorch-lightning
Code Injection in GitHub repository pytorchlightning/pytorch-lightning prior to 1.6.0.
Other sources
PyTorch Lightning version 1.5.10 and prior is vulnerable to code injection. An attacker could execute commands on the target OS running the operating system by setting the PLTRAINERGPUS when using the Trainer module. A patch is included in the 1.6.0 release.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2022-0845?
CVE-2022-0845 is classified as a high-severity vulnerability due to its potential for code execution.
How do I fix CVE-2022-0845?
To fix CVE-2022-0845, upgrade to PyTorch Lightning version 1.6.0 or later.
What is the nature of the vulnerability in CVE-2022-0845?
CVE-2022-0845 is a code injection vulnerability that allows attackers to execute arbitrary commands on the host OS.
Which versions are affected by CVE-2022-0845?
CVE-2022-0845 affects PyTorch Lightning versions prior to 1.6.0, including 1.5.10 and earlier releases.
Who is impacted by CVE-2022-0845?
Developers and organizations using affected versions of PyTorch Lightning are at risk due to CVE-2022-0845.