CVE-2024-34997
published 2024-05-17CVE-2024-34997: joblib v1.4.2 was discovered to contain a deserialization vulnerability via the component joblib.numpy_pickle::NumpyArrayWrapper().read_array(). NOTE: this is…
PriorityP337high7.5CVSS 3.1
AVNACHPRLUINSUCHIHAH
EPSS
0.66%
48.1th percentile
joblib v1.4.2 was discovered to contain a deserialization vulnerability via the component joblib.numpy_pickle::NumpyArrayWrapper().read_array(). NOTE: this is disputed by the supplier because NumpyArrayWrapper is only used during caching of trusted content.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | joblib | — | — |
| joblib_project | joblib | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.5HIGH
vendor_debian7.5LOW
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
python-joblib: Deserialization vulnerability via joblib.numpy_pickle::NumpyArrayWrapper().read_array()
vendor_redhat·2024-05-17·CVSS 7.5
CVE-2024-34997 [HIGH] CWE-502 python-joblib: Deserialization vulnerability via joblib.numpy_pickle::NumpyArrayWrapper().read_array()
python-joblib: Deserialization vulnerability via joblib.numpy_pickle::NumpyArrayWrapper().read_array()
joblib v1.4.2 was discovered to contain a deserialization vulnerability via the component joblib.numpy_pickle::NumpyArrayWrapper().read_array(). NOTE: this is disputed by the supplier because NumpyArrayWrapper is only used during caching of trusted content.
A flaw was found in python-joblib. A deserialization vulnerability via the joblib.numpy_pickle::NumpyArrayWrapper().read_array() component uses the insecure pickle python library when used with untrusted inputs.
Statement: The pickle python library is known to be insecure and should not be used to parse untrusted data.
No Red Hat product ships this package directly, therefore the impact for this issue is set as Moderate.
Package: a
Debian
CVE-2024-34997: joblib - joblib v1.4.2 was discovered to contain a deserialization vulnerability via the ...
vendor_debian·2024·CVSS 7.5
CVE-2024-34997 [HIGH] CVE-2024-34997: joblib - joblib v1.4.2 was discovered to contain a deserialization vulnerability via the ...
joblib v1.4.2 was discovered to contain a deserialization vulnerability via the component joblib.numpy_pickle::NumpyArrayWrapper().read_array(). NOTE: this is disputed by the supplier because NumpyArrayWrapper is only used during caching of trusted content.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
OSV
CVE-2024-34997: joblib v1
osv·2024-05-17·CVSS 7.5
CVE-2024-34997 [HIGH] CVE-2024-34997: joblib v1
joblib v1.4.2 was discovered to contain a deserialization vulnerability via the component joblib.numpy_pickle::NumpyArrayWrapper().read_array(). NOTE: this is disputed by the supplier because NumpyArrayWrapper is only used during caching of trusted content.
OSV
CVE-2024-34997: ** DISPUTED ** joblib v1
osv·2024-05-17·CVSS 7.5
CVE-2024-34997 [HIGH] CVE-2024-34997: ** DISPUTED ** joblib v1
** DISPUTED ** joblib v1.4.2 was discovered to contain a deserialization vulnerability via the component joblib.numpy_pickle::NumpyArrayWrapper().read_array(). NOTE: this is disputed by the supplier because NumpyArrayWrapper is only used during caching of trusted content.
GHSA
GHSA-rf65-fc2p-2gjv: joblib v1
ghsa_unreviewed·2024-05-17
CVE-2024-34997 GHSA-rf65-fc2p-2gjv: joblib v1
joblib v1.4.2 was discovered to contain a deserialization vulnerability via the component joblib.numpy_pickle::NumpyArrayWrapper().read_array().
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-05-17
Published