Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-6958 | In the latest version of pytorch/serve, the script 'upload_results_to_s3.sh' references the S3 bucket 'benchmarkai-metrics-prod' without ensuring its ownership or confirming its accessibility. This could lead to potential security vulnerabilities or unauthorized access to the bucket if it is not properly secured or claimed by the appropriate entity. The issue may result in data breaches, exposure of proprietary information, or unauthorized modifications to stored data. |
Github GHSA |
GHSA-xx7c-j7h3-vjcq | TorchServe script references S3 bucket without ensuring ownership or confirming accessibility |
Thu, 20 Mar 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 20 Mar 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In the latest version of pytorch/serve, the script 'upload_results_to_s3.sh' references the S3 bucket 'benchmarkai-metrics-prod' without ensuring its ownership or confirming its accessibility. This could lead to potential security vulnerabilities or unauthorized access to the bucket if it is not properly secured or claimed by the appropriate entity. The issue may result in data breaches, exposure of proprietary information, or unauthorized modifications to stored data. | |
| Title | Unclaimed S3 Bucket Usage in pytorch/serve | |
| Weaknesses | CWE-840 | |
| References |
| |
| Metrics |
cvssV3_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: @huntr_ai
Published:
Updated: 2025-03-20T18:19:07.501Z
Reserved: 2024-07-08T17:46:40.922Z
Link: CVE-2024-6577
Updated: 2025-03-20T17:48:14.962Z
Status : Deferred
Published: 2025-03-20T10:15:32.987
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-6577
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA