SCA: security update for lightning (GHSA-cgwc-qvrx-rf7f)

critical Tenable Cloud Security Plugin ID 421387

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- A remote code execution (RCE) vulnerability exists in the lightning-ai/pytorch-lightning library version
2.2.1 due to improper handling of deserialized user input and mismanagement of dunder attributes by the
`deepdiff` library. The library uses `deepdiff.Delta` objects to modify application state based on
frontend actions. However, it is possible to bypass the intended restrictions on modifying dunder
attributes, allowing an attacker to construct a serialized delta that passes the deserializer whitelist
and contains dunder attributes. When processed, this can be exploited to access other modules, classes,
and instances, leading to arbitrary attribute write and total RCE on any self-hosted pytorch-lightning
application in its default configuration, as the delta endpoint is enabled by default. (CVE-2024-5452)

See Also

https://github.com/advisories/GHSA-cgwc-qvrx-rf7f

Plugin Details

Severity: Critical

ID: 421387

Version: Revision 1.3

Type: Local

Family: SCA Checks

Published: 3/28/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.88

Vendor

Vendor Severity: Critical

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2024-5452

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 6/6/2024

Vulnerability Publication Date: 6/6/2024

Reference Information

CVE: CVE-2024-5452