
Detailed technical analysis of CVE-2024-5452, a remote code execution vulnerability in PyTorch Lightning via DeepDiff delta property pollution, with proof-of-concept and mitigation guidance.
RCE (Remote Code Execution) is a vulnerability that allows an attacker to execute arbitrary code remotely within a system or application, and is classified as CWE-94: Improper Control of Generation of Code ('Code Injection').
PyTorch Lightning is a library that helps easily manage deep learning model training based on PyTorch, and DeepDiff is a library that analyzes differences by comparing two Python objects.
CVE-2024-5452 is a vulnerability that causes RCE during deserialization through weak header validation of DeepDiff and delta attribute contamination in the process of utilizing DeepDiff and Lightning in Lightning's AI model weight-related web application features.
Through this, we will examine the code flow that leads to vulnerabilities allowing an attacker to inject arbitrary objects or perform remote code execution (RCE), and explore countermeasures.
[Figure 1] POC - Endpoint attack
[Figure 2] POC - Vuln Injection / Full contamination setup content
[Figure 3] lightning/api/core/api.py / Weak header validation logic part
[Figure 4] lightning/api/core/app.py / Setup section
[Figure 5] lightning/api/core/app.py / State storage section