Allocation of Resources Without Limits or Throttling in nvflare
High7.5CVE-2022-21822 · Published Mar 17, 2022 · updated Mar 18, 2022
### Impact NVIDIA FLARE contains a vulnerability in Admin Interface, where an un-authorized attacker can cause Allocation of Resources Without Limits or Throttling, which may lead to cause system unavailable All versions before 2.0.16 are affected. ### Patches The patch will be included in nvflare==2.0.16. ### Workarounds The changes in commits https://github.com/NVIDIA/NVFlare/commit/93588b3a0dff9bd4568983071b74d8b420de3a6e and https://github.com/NVIDIA/NVFlare/commit/93588b3a0dff9bd4568983071b74d8b420de3a6e can be applied to any version of the NVIDIA FLARE without any adverse effect. ### Additional information Issue Found on: 2022.3.3 Issue Found by: Oliver Sellwood (@Nintorac)
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| nvflare PyPI | < 2.0.16 | 2.0.16 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-770
More Nvidia advisories
All Nvidia| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 1 | Nvidia BlueField GA: code execution | Critical9.0 | No fix yet |
| Oct 82024 | Nvidia: tampering | Medium4.1 | 1.16.2+2 more |
| Oct 82024 | Nvidia: race condition | Critical9.0 | 1.16.2+2 more |
| Aug 222022 | NVFLARE unsafe deserialization due to Pickle | Critical | 2.1.4 |
| Jun 212022 | Unsafe yaml deserialization | Critical | 2.1.2 |
| Jun 212022 | Unsafe deserialisation in the PKI implementation scheme | Critical | 2.1.2 |