CVE-2024-8238
Description
In version 3.22.0 of aimhubio/aim, the AimQL query language uses an outdated version of the safer_getattr() function from RestrictedPython. This version does not protect against the str.format_map() method, allowing an attacker to leak server-side secrets or potentially gain unrestricted code execution. The vulnerability arises because str.format_map() can read arbitrary attributes of Python objects, enabling attackers to access sensitive variables such as os.environ. If an attacker can write files to a known location on the Aim server, they can use str.format_map() to load a malicious .dll/.so file into the Python interpreter, leading to unrestricted code execution.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
aimPyPI | >= 3.0.0, <= 3.22.0 | — |
Affected products
3- aimhubio/aimhubio/aimv5Range: unspecified
Patches
Vulnerability mechanics
References
4- huntr.com/bounties/4e140ef9-f6d1-4e68-a44c-3b9e856924d3nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-r229-5wgf-f28gghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-8238ghsaADVISORY
- github.com/aimhubio/aim/blob/main/aim/storage/query.pyghsaWEB
News mentions
0No linked articles in our index yet.