Metrics
Affected Vendors & Products
Tue, 01 Apr 2025 17:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_0
|
cvssV3_0
|
Tue, 01 Apr 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Title | Deserialization of Untrusted Data in pytorch/pytorch | pytorch: Deserialization of Untrusted Data in pytorch/pytorch |
Metrics |
ssvc
|
Tue, 01 Apr 2025 17:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A deserialization vulnerability exists in the Pytorch RPC framework (torch.distributed.rpc) in pytorch/pytorch versions <=2.3.1. The vulnerability arises from the lack of security verification during the deserialization process of PythonUDF objects in pytorch/torch/distributed/rpc/internal.py. This flaw allows an attacker to execute arbitrary code remotely by sending a malicious serialized PythonUDF object, leading to remote code execution (RCE) on the master node. | This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
Tue, 25 Mar 2025 01:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
| |
Metrics |
threat_severity
|
threat_severity
|
Thu, 20 Mar 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 20 Mar 2025 10:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A deserialization vulnerability exists in the Pytorch RPC framework (torch.distributed.rpc) in pytorch/pytorch versions <=2.3.1. The vulnerability arises from the lack of security verification during the deserialization process of PythonUDF objects in pytorch/torch/distributed/rpc/internal.py. This flaw allows an attacker to execute arbitrary code remotely by sending a malicious serialized PythonUDF object, leading to remote code execution (RCE) on the master node. | |
Title | Deserialization of Untrusted Data in pytorch/pytorch | |
Weaknesses | CWE-502 | |
References |
| |
Metrics |
cvssV3_0
|

Status: REJECTED
Assigner: @huntr_ai
Published:
Updated: 2025-04-01T16:46:40.738Z
Reserved: 2024-08-14T16:45:16.341Z
Link: CVE-2024-7804

Updated:

Status : Rejected
Published: 2025-03-20T10:15:37.767
Modified: 2025-04-01T17:15:44.567
Link: CVE-2024-7804
