onnx

Open standard for machine learning interoperability

Version: 1.7.0 registry icon
Safety score
0
Check your open source dependency risks. Get immediate insight about security, stability and licensing risks.
Security Risks of Known Vulnerabilities
CVE-2022-25882
CWE-22
Threat level: HIGH | CVSS score: 7.5

Versions of the package onnx before 1.13.0 are vulnerable to Directory Traversal as the external_data field of the tensor proto can have a path to the file which is outside the model current directory or user-provided directory, for example "../../../etc/passwd"



CVE-2024-7776
CWE-22
Threat level: HIGH | CVSS score: 8

A vulnerability in the download_model function of the onnx/onnx framework, before and including version 1.16.1, allows for arbitrary file overwrite due to inadequate prevention of path traversal attacks in malicious tar files. This vulnerability can be exploited by an attacker to overwrite files in the user's directory, potentially leading to remote command execution.



CVE-2024-27318
CWE-22
Threat level: HIGH | CVSS score: 7.5

Versions of the package onnx before and including 1.15.0 are vulnerable to Directory Traversal as the external_data field of the tensor proto can have a path to the file which is outside the model current directory or user-provided directory. The vulnerability occurs as a bypass for the patch added for CVE-2022-25882.



CVE-2024-27319
CWE-125
Threat level: HIGH | CVSS score: 9.1

Versions of the package onnx before and including 1.15.0 are vulnerable to Out-of-bounds Read as the ONNX_ASSERT and ONNX_ASSERTM functions have an off by one string copy.



Please note that this component is affected by another vulnerability
0 Critical  |  1 High  |  0 Medium  |  0 Low  |  0 Suggest

Latest safe minor: 1.17.0 Scan your application codebase with Meterian to see all known vulnerabilities in your open source software dependencies.


Stability

Stay updated with the latest patches and releases. Plan your sofware desisgn. Avoid common known vulnerabilities fixed by the open source community

Latest patch release:   --

Latest minor release:   1.17.0

Latest major release:   --

Licensing

Maintain your licence declarations and avoid unwanted licences to protect your IP the way you intended.

We were not able to detect a valid license on this component. We recommend not to use this component.