GHSA for Command Injection in capture_dependencies
High7.8CVE-2024-34073 · Published May 2, 2024 · updated May 3, 2024
### Impact The capture_dependencies function in `sagemaker.serve.save_retrive.version_1_0_0.save.utils` module before version 2.214.3 allows for potentially unsafe Operating System (OS) Command Injection if inappropriate command is passed as the “requirements_path” parameter. This consequently may allow an unprivileged third party to cause remote code execution, denial of service, affecting both confidentiality and integrity. Impacted versions: <2.214.3 ### Credit We would like to thank HiddenLayer for collaborating on this issue through the coordinated vulnerability disclosure process. ### Workarounds Do not override the “requirements_path” parameter of capture_dependencies function in `sagemaker.serve.save_retrive.version_1_0_0.save.utils`, instead use the default value. ### References If you have any questions or comments about this advisory we ask that you contact AWS/Amazon Security via our vulnerability reporting page [1] or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. [1] Vulnerability reporting page: https://aws.amazon.com/security/vulnerability-reporting Fixed by: https://github.com/aws/sagemaker-python-sdk/pull/4556
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| sagemaker-python-sdk Product | < 2.214.3 | 2.214.3 |
Details and references
### Impact The capture_dependencies function in `sagemaker.serve.save_retrive.version_1_0_0.save.utils` module before version 2.214.3 allows for potentially unsafe Operating System (OS) Command Injection if inappropriate command is passed as the “requirements_path” parameter. This consequently may allow an unprivileged third party to cause remote code execution, denial of service, affecting both confidentiality and integrity. Impacted versions: <2.214.3 ### Credit We would like to thank HiddenLayer for collaborating on this issue through the coordinated vulnerability disclosure process. ### Workarounds Do not override the “requirements_path” parameter of capture_dependencies function in `sagemaker.serve.save_retrive.version_1_0_0.save.utils`, instead use the default value. ### References If you have any questions or comments about this advisory we ask that you contact AWS/Amazon Security via our vulnerability reporting page [1] or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. [1] Vulnerability reporting page: https://aws.amazon.com/security/vulnerability-reporting Fixed by: https://github.com/aws/sagemaker-python-sdk/pull/4556
- CVSS 3.1
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-78
More AWS advisories
All AWS| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 112024 | Sensitive Information Exposure Through Insecure Logging For Secrets Like Metadata.DockerBuildArgs | High | 1.122.0 |
| Aug 272024 | AWS CDK RestApi Construct: Authenticated users may have unintended access to protected APIs | Medium6.4 | 2.148.1 |
| Aug 92024 | mTLS API ordering may skip client authentication | Medium | v1.5.0+1 more |
| Jul 192024 | Potential weak encryption of session ticket | High | v1.4.18 |
| Jun 52024 | Potentially observable differences in RSA premaster secret handling | Low | v1.4.16+1 more |
| May 22024 | GHSA for sagemaker.base_deserializers.NumpyDeserializer | High7.8 | 2.218.0 |