CVE-2024-34997

Name
CVE-2024-34997
Description
joblib v1.4.2 was discovered to contain a deserialization vulnerability via the component joblib.numpy_pickle::NumpyArrayWrapper().read_array(). NOTE: this is disputed by the supplier because NumpyArrayWrapper is only used during caching of trusted content.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
cve@mitre.org https://github.com/joblib/joblib/issues/1582
Exploit https://github.com/joblib/joblib/issues/977

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:joblib_project:joblib:1.4.2:*:*:*:*:python:*:* py3-joblib == None == 1.4.2

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
py3-joblib edge-community 1.4.2-r0 Bart Ribbers <bribbers@disroot.org> possibly vulnerable
py3-joblib 3.22-community 1.4.2-r0 Bart Ribbers <bribbers@disroot.org> possibly vulnerable