Skip to content
NvidiaGHSA-jx8f-cpx7-fv47

Allocation of Resources Without Limits or Throttling in nvflare

High7.5CVE-2022-21822 · Published Mar 17, 2022 · updated Mar 18, 2022

### Impact NVIDIA FLARE contains a vulnerability in Admin Interface, where an un-authorized attacker can cause Allocation of Resources Without Limits or Throttling, which may lead to cause system unavailable All versions before 2.0.16 are affected. ### Patches The patch will be included in nvflare==2.0.16. ### Workarounds The changes in commits https://github.com/NVIDIA/NVFlare/commit/93588b3a0dff9bd4568983071b74d8b420de3a6e and https://github.com/NVIDIA/NVFlare/commit/93588b3a0dff9bd4568983071b74d8b420de3a6e can be applied to any version of the NVIDIA FLARE without any adverse effect. ### Additional information Issue Found on: 2022.3.3 Issue Found by: Oliver Sellwood (@Nintorac)

GitHub advisory

Affected versions

PackageAffectedFixed in
nvflare
PyPI
< 2.0.162.0.16
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-770

More Nvidia advisories

All Nvidia
Advisory
Nvidia BlueField GA: code execution
Critical9.0Jul 1
Nvidia: tampering
Medium4.1Oct 8, 2024
Nvidia: race condition
Critical9.0Oct 8, 2024
NVFLARE unsafe deserialization due to Pickle
CriticalAug 22, 2022
Unsafe yaml deserialization
CriticalJun 21, 2022
Unsafe deserialisation in the PKI implementation scheme
CriticalJun 21, 2022

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.