Skip to content

Conversation

@abdel91
Copy link
Contributor

@abdel91 abdel91 commented Oct 7, 2022

The package joblib from 0 and before 1.2.0 are vulnerable to Arbitrary Code Execution via the pre_dispatch flag in Parallel() class due to the eval() statement.

@google-cla
Copy link

google-cla bot commented Oct 7, 2022

Thanks for your pull request! It looks like this may be your first contribution to a Google open source project. Before we can look at your pull request, you'll need to sign a Contributor License Agreement (CLA).

View this failed invocation of the CLA check for more information.

For the most up to date status, view the checks section at the bottom of the pull request.

@abdel91 abdel91 changed the title Update joblib version to fix CVE-2022-21797 Update the joblib version to fix CVE-2022-21797 Oct 7, 2022
@singhniraj08
Copy link

@caveness,

Kindly review this PR and approve it. Older version of joblib is blocking users because of security vulnerability. #226

Thank you!

Copy link
Collaborator

@caveness caveness left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks!

@caveness caveness merged commit 32183ed into tensorflow:master Oct 28, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants