CVE-2024-0129: Path Traversal
NVIDIA NeMo contains a vulnerability in SaveRestoreConnector where a user may cause a path traversal issue via an unsafe .tar file extraction. A successful exploit of this vulnerability may lead to code execution and data tampering.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-0129?
CVE-2024-0129 is classified as a high severity vulnerability due to its potential for code execution and data tampering.
How do I fix CVE-2024-0129?
To fix CVE-2024-0129, update NVIDIA NeMo to a version beyond r2.0.0rc0 that addresses the path traversal issue.
What causes the CVE-2024-0129 vulnerability?
CVE-2024-0129 is caused by an unsafe extraction of .tar files within the SaveRestoreConnector component of NVIDIA NeMo.
Who is affected by CVE-2024-0129?
Users of NVIDIA NeMo versions up to and including r2.0.0rc0 are affected by CVE-2024-0129.
What are the potential impacts of exploiting CVE-2024-0129?
Exploiting CVE-2024-0129 could lead to unauthorized code execution and data tampering on affected systems.