Description
TorchServe is a flexible and easy-to-use tool for serving and scaling PyTorch models in production. In the default configuration, TorchServe is vulnerable to an SSRF vulnerability. An attacker could exploit this vulnerability to compromise the server.
Remediation
Set secure values for the allowed_urls option and the model URL in the TorchServe
References
Related Vulnerabilities
MySQL CVE-2014-0420 Vulnerability (CVE-2014-0420)
Plone CMS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2012-5508)
Oracle JRE CVE-2023-21937 Vulnerability (CVE-2023-21937)
Oracle Database Server CVE-2011-0882 Vulnerability (CVE-2011-0882)
phpMyFAQ Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2014-6046)