[Bug 1204232] New: VUL-0: CVE-2022-21797: python-joblib: Arbitrary Code Execution in joblib
http://bugzilla.opensuse.org/show_bug.cgi?id=1204232 Bug ID: 1204232 Summary: VUL-0: CVE-2022-21797: python-joblib: Arbitrary Code Execution in joblib Classification: openSUSE Product: openSUSE Distribution Version: Leap 15.4 Hardware: Other URL: https://smash.suse.de/issue/343589/ OS: Other Status: NEW Severity: Major Priority: P5 - None Component: Security Assignee: dmueller@suse.com Reporter: thomas.leroy@suse.com QA Contact: security-team@suse.de Found By: Security Response Team Blocker: --- rh#2129823 The package joblib from 0 and before 1.2.0 are vulnerable to Arbitrary Code Execution via the pre_dispatch flag in Parallel() class due to the eval() statement. https://github.com/joblib/joblib/commit/b90f10efeb670a2cc877fb88ebb3f2019189... https://github.com/joblib/joblib/issues/1128 https://github.com/joblib/joblib/pull/1321 https://security.snyk.io/vuln/SNYK-PYTHON-JOBLIB-3027033 References: https://bugzilla.redhat.com/show_bug.cgi?id=2129823 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-21797 https://github.com/joblib/joblib/commit/b90f10efeb670a2cc877fb88ebb3f2019189... https://github.com/joblib/joblib/issues/1128 http://www.cvedetails.com/cve/CVE-2022-21797/ https://github.com/joblib/joblib/pull/1321 https://www.cve.org/CVERecord?id=CVE-2022-21797 https://security.snyk.io/vuln/SNYK-PYTHON-JOBLIB-3027033 https://lists.fedoraproject.org/archives/list/package-announce@lists.fedorap... -- You are receiving this mail because: You are on the CC list for the bug.
http://bugzilla.opensuse.org/show_bug.cgi?id=1204232 http://bugzilla.opensuse.org/show_bug.cgi?id=1204232#c1 --- Comment #1 from Thomas Leroy <thomas.leroy@suse.com> --- Affected codestreams: - openSUSE:Factory - openSUSE:Backports:SLE-15-SP3 -- You are receiving this mail because: You are on the CC list for the bug.
http://bugzilla.opensuse.org/show_bug.cgi?id=1204232 http://bugzilla.opensuse.org/show_bug.cgi?id=1204232#c3 --- Comment #3 from OBSbugzilla Bot <bwiedemann+obsbugzillabot@suse.com> --- This is an autogenerated message for OBS integration: This bug (1204232) was mentioned in https://build.opensuse.org/request/show/1010179 Factory / python-joblib -- You are receiving this mail because: You are on the CC list for the bug.
http://bugzilla.opensuse.org/show_bug.cgi?id=1204232 http://bugzilla.opensuse.org/show_bug.cgi?id=1204232#c4 --- Comment #4 from OBSbugzilla Bot <bwiedemann+obsbugzillabot@suse.com> --- This is an autogenerated message for OBS integration: This bug (1204232) was mentioned in https://build.opensuse.org/request/show/1020839 Backports:SLE-15-SP3 / python-joblib -- You are receiving this mail because: You are on the CC list for the bug.
participants (1)
-
bugzilla_noreply@suse.com