Exploit Report

Computer Security And Bug Information

CVE-2022-21797

CVECVE-2022-21797
CVE Ordinal Value229584
Published Date2022-09-26T05:15Z
Modified Date2022-09-27T04:52Z
CWE TypeNVD-CWE-noinfo
CVSS 3.xCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
DescriptionThe package joblib from 0 and before 1.2.0 are vulnerable to Arbitrary Code Execution via the pre_dispatch flag in Parallel() class due to the eval() statement.
References
By clicking these links you will leave this website. We do not endorse and will not be held accountable for any activity on external sites.
Reference URLhttps://github.com/joblib/joblib/commit/b90f10efeb670a2cc877fb88ebb3f2019189e059
Reference DescriptionCONFIRM N/A
Reference URLhttps://github.com/joblib/joblib/issues/1128
Reference DescriptionCONFIRM N/A
Reference URLhttps://github.com/joblib/joblib/pull/1321
Reference DescriptionCONFIRM N/A
Reference URLhttps://security.snyk.io/vuln/SNYK-PYTHON-JOBLIB-3027033
Reference DescriptionCONFIRM N/A
TagsPatch Third Party Advisory
Sources NIST MITRE

This site's data is aggregated programmatically and provided "as is" without any representations or warranties, express or implied. Exploit.report is not affiliated with the The MITRE Corporation, U.S. Department of Homeland Security (DHS), Cybersecurity and Infrastructure Security Agency (CISA), or US government in any way. CVE and the CVE logo are registered trademarks of The MITRE Corporation

© 2022 Exploit.Report | Data | Contact | Privacy Policy | Articles