Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Arbitrary Code Execution
Vulnerability Description
The package joblib from 0 and before 1.2.0 are vulnerable to Arbitrary Code Execution via the pre_dispatch flag in Parallel() class due to the eval() statement.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Vulnerability Type
N/A
Vulnerability Title
joblib 安全漏洞
Vulnerability Description
joblib是joblib开源的一组在 Python 中提供轻量级流水线的工具。 joblib package 1.2.0之前的版本存在安全漏洞,该漏洞源于其Parallel()类中的pre_dispatch标志允许攻击者通过eval()语句实现任意代码执行。
CVSS Information
N/A
Vulnerability Type
N/A