Amazon Deep Java Library (DJL) 版本 0.13.0 至 0.36.0 的张量缓冲区验证组件中存在整数溢出漏洞,可能允许远程未认证的攻击者通过构造的张量负载,从相邻进程内存中获取信息或导致服务拒绝(DoS)。 要修复此问题,用户应升级到 0.37.0 或更高版本。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Amazon | Deep Java Library | 0.13.0≤ 0.36.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Amazon | Deep Java Library | 0.13.0 ~ 0.36.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet