Skip to content

Path traversal in emergency P2P checkpoint service allows arbitrary file write on training host #3106

@YuvalElbar6

Description

@YuvalElbar6

A path-traversal vulnerability in the emergency P2P checkpoint service allows
a network peer to write files outside the intended staging directory on the
victim host.

Reported to the Google OSS VRP; per OSS VRP policy the report is held until
a patch is merged upstream.

A fix is proposed in #3105.

Metadata

Metadata

Assignees

No one assigned

    Labels

    type:bugSomething isn't working

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions