7.5
CVSSv3

CVE-2022-25882

Published: 26/01/2023 Updated: 07/11/2023
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

Versions of the package onnx prior to 1.13.0 are vulnerable to Directory Traversal as the external_data field of the tensor proto can have a path to the file which is outside the model current directory or user-provided directory, for example "../../../etc/passwd"

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

linuxfoundation onnx