CVE-2022-21797
Summary
| CVE | CVE-2022-21797 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-09-26 05:15:00 UTC |
| Updated | 2024-01-02 16:15:00 UTC |
| Description | The package joblib from 0 and before 1.2.0 are vulnerable to Arbitrary Code Execution via the pre_dispatch flag in Parallel() class due to the eval() statement. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Debian | Debian Linux | 10.0 | All | All | All |
| Operating System | Fedoraproject | Fedora | 36 | All | All | All |
| Operating System | Fedoraproject | Fedora | 37 | All | All | All |
| Application | Joblib Project | Joblib | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| FIX make sure pre_dispatch cannot do arbitrary code execution by adrinjalali · Pull Request #1321 · joblib/joblib · GitHub | CONFIRM | github.com | |
| [SECURITY] Fedora 36 Update: python-joblib-1.2.0-1.fc36 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| [SECURITY] Fedora 36 Update: python-joblib-1.2.0-1.fc36 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| Arbitrary Code Execution in joblib | CVE-2022-21797 | Snyk | CONFIRM | security.snyk.io | |
| [SECURITY] [DLA 3193-2] joblib security update | MLIST | lists.debian.org | |
| [SECURITY] [DLA 3193-1] joblib security update | MLIST | lists.debian.org | |
| [SECURITY] Fedora 37 Update: python-joblib-1.2.0-1.fc37 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| The potential security vulnerability for the flag pre_dispatch in Parallel() class due to the eval() statement. · Issue #1128 · joblib/joblib · GitHub | CONFIRM | github.com | |
| FIX make sure pre_dispatch cannot do arbitrary code execution (#1321) · joblib/joblib@b90f10e · GitHub | CONFIRM | github.com | |
| GLSA-202401-01 | security.gentoo.org | ||
| [SECURITY] Fedora 37 Update: python-joblib-1.2.0-1.fc37 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Jim Lin
Legacy QID Mappings
- 181228 Debian Security Update for joblib (DLA 3193-1)
- 181644 Debian Security Update for joblib (DLA 3193-2)
- 283192 Fedora Security Update for python (FEDORA-2022-c0bfe37ae5)
- 502923 Alpine Linux Security Update for py3-joblib
- 505802 Alpine Linux Security Update for py3-joblib
- 691121 Free Berkeley Software Distribution (FreeBSD) Security Update for py39 (845f8430-d0ee-4134-ae35-480a3e139b8a)
- 710819 Gentoo Linux Joblib Arbitrary Code Execution Vulnerability (GLSA 202401-01)