Joblib Project Joblib vulnerabilities
2 known vulnerabilities affecting joblib_project/joblib.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH1
Vulnerabilities
Page 1 of 1
CVE-2024-34997HIGHCVSS 7.5v1.4.22024-05-17
CVE-2024-34997 [HIGH] CWE-502 CVE-2024-34997: joblib v1.4.2 was discovered to contain a deserialization vulnerability via the component joblib.num
joblib v1.4.2 was discovered to contain a deserialization vulnerability via the component joblib.numpy_pickle::NumpyArrayWrapper().read_array(). NOTE: this is disputed by the supplier because NumpyArrayWrapper is only used during caching of trusted content.
nvd
CVE-2022-21797CRITICALCVSS 9.8fixed in 1.1.1fixed in unspecified+1 more2022-09-26
CVE-2022-21797 [CRITICAL] CWE-94 CVE-2022-21797: The package joblib from 0 and before 1.2.0 are vulnerable to Arbitrary Code Execution via the pre_di
The package joblib from 0 and before 1.2.0 are vulnerable to Arbitrary Code Execution via the pre_dispatch flag in Parallel() class due to the eval() statement.
ghsanvdosv