Vulnerabilities
Vulnerable Software
Joblib Project:  >> Joblib  Security Vulnerabilities
joblib v1.4.2 was discovered to contain a deserialization vulnerability via the component joblib.numpy_pickle::NumpyArrayWrapper().read_array(). NOTE: this is disputed by the supplier because NumpyArrayWrapper is only used during caching of trusted content.
CVSS Score
7.5
EPSS Score
0.005
Published
2024-05-17
The package joblib from 0 and before 1.2.0 are vulnerable to Arbitrary Code Execution via the pre_dispatch flag in Parallel() class due to the eval() statement.
CVSS Score
7.3
EPSS Score
0.002
Published
2022-09-26


Contact Us

Shodan ® - All rights reserved