Lucene search

K
cvelistMitreCVELIST:CVE-2024-34997
HistoryMay 17, 2024 - 12:00 a.m.

CVE-2024-34997

2024-05-1700:00:00
mitre
www.cve.org
4
joblib
v1.4.2
deserialization
vulnerability
numpy_pickle
numpyarraywrapper
read_array
caching
trusted content

AI Score

6.8

Confidence

High

EPSS

0

Percentile

9.0%

joblib v1.4.2 was discovered to contain a deserialization vulnerability via the component joblib.numpy_pickle::NumpyArrayWrapper().read_array(). NOTE: this is disputed by the supplier because NumpyArrayWrapper is only used during caching of trusted content.

AI Score

6.8

Confidence

High

EPSS

0

Percentile

9.0%