1.21.0
8 years ago
24 days ago
Known vulnerabilities in the onnx package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
onnx is an Open Neural Network Exchange Affected versions of this package are vulnerable to Time-of-check Time-of-use (TOCTOU) Race Condition through the How to fix Time-of-check Time-of-use (TOCTOU) Race Condition? Upgrade | [,1.21.0) |
onnx is an Open Neural Network Exchange Affected versions of this package are vulnerable to Improperly Controlled Modification of Dynamically-Determined Object Attributes in the How to fix Improperly Controlled Modification of Dynamically-Determined Object Attributes? Upgrade | [,1.21.0) |
onnx is an Open Neural Network Exchange Affected versions of this package are vulnerable to UNIX Symbolic Link (Symlink) Following via the How to fix UNIX Symbolic Link (Symlink) Following? Upgrade | [,1.21.0) |
onnx is an Open Neural Network Exchange Affected versions of this package are vulnerable to UNIX Symbolic Link (Symlink) Following in the How to fix UNIX Symbolic Link (Symlink) Following? Upgrade | [,1.21.0) |
onnx is an Open Neural Network Exchange Affected versions of this package are vulnerable to UNIX Symbolic Link (Symlink) Following through the handling of external data files when symbolic links are present. An attacker can access arbitrary files on the host system by crafting a symlink that points to sensitive files and providing it alongside a model file to a victim, who then loads the model and inadvertently exposes the targeted files. How to fix UNIX Symbolic Link (Symlink) Following? Upgrade | [,1.21.0) |
onnx is an Open Neural Network Exchange Affected versions of this package are vulnerable to Resources Downloaded over Insecure Protocol via the How to fix Resources Downloaded over Insecure Protocol? Upgrade | [0,1.21.0) |
onnx is an Open Neural Network Exchange Affected versions of this package are vulnerable to Directory Traversal via the How to fix Directory Traversal? Upgrade | [0,1.21.0) |