CVE-2024-2195 Information
Apr 11, 2024
cve
Description
A critical Remote Code Execution (RCE) vulnerability was identified in the aimhubio/aim project specifically within the /api/runs/search/run/ endpoint affecting versions >= 3.0.0. The vulnerability resides in the run_search_api function of the aim/web/api/runs/views.py file where improper restriction of user access to the RunView object allows for the execution of arbitrary code via the query parameter. This issue enables attackers to execute arbitrary commands on the server potentially leading to full system compromise.
Reference
https://huntr.com/bounties/22f2355e-b875-4c01-b454-327e5951c018
Share on: