Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2022-36022— Some Deeplearning4J packages use unclaimed s3 bucket in tests and examples

Quick assessment

Affected
eclipse deeplearning4j
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Eclipse Deeplearning4J(Eclipse DL4J)是Eclipse基金会的一组旨在支持基于 JVM 的深度学习应用程序的所有需求的项目。 Eclipse Deeplearning4J 1.0.0-M2.1及之前版本存在安全漏洞,该漏洞源于可能会在示例测试中使用一些无人认领的S3存储桶,这可能会影响使用一些引用旧S3存储桶的旧NLP示例的人。

CVSS 5.3 · Medium EPSS 0.42% · P34

Possible ATT&CK Techniques 2 AI

T1583.001 · Domains T1588.001 · Malware
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2022-36022

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Some Deeplearning4J packages use unclaimed s3 bucket in tests and examples
Source: CVE Program / CVE List V5
Vulnerability Description
Deeplearning4J is a suite of tools for deploying and training deep learning models using the JVM. Packages org.deeplearning4j:dl4j-examples and org.deeplearning4j:platform-tests through version 1.0.0-M2.1 may use some unclaimed S3 buckets in tests in examples. This is likely affect people who use some older NLP examples that reference an old S3 bucket. The problem has been patched. Users should upgrade to snapshots as Deeplearning4J plan to publish a release with the fix at a later date. As a workaround, download a word2vec google news vector from a new source using git lfs from here.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
在动态变化上下文中使用不变值
Source: CVE Program / CVE List V5
Vulnerability Title
Eclipse Deeplearning4J 安全特征问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Eclipse Deeplearning4J(Eclipse DL4J)是Eclipse基金会的一组旨在支持基于 JVM 的深度学习应用程序的所有需求的项目。 Eclipse Deeplearning4J 1.0.0-M2.1及之前版本存在安全漏洞,该漏洞源于可能会在示例测试中使用一些无人认领的S3存储桶,这可能会影响使用一些引用旧S3存储桶的旧NLP示例的人。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
eclipse deeplearning4j <= 1.0.0-M2.1 -

II. Public POCs for CVE-2022-36022

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2022-36022

请登录查看更多情报信息。

Vendor Advisories for CVE-2022-36022 (1)

Other References for CVE-2022-36022 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2022-36022

No comments yet


Leave a comment