Lucene search

K
ubuntucveUbuntu.comUB:CVE-2024-34997
HistoryMay 17, 2024 - 12:00 a.m.

CVE-2024-34997

2024-05-1700:00:00
ubuntu.com
ubuntu.com
11
cve-2024-34997
joblib
deserialization vulnerability
numpyarraywrapper
unix

AI Score

6.9

Confidence

High

EPSS

0

Percentile

9.0%

DISPUTED joblib v1.4.2 was discovered to contain a deserialization
vulnerability via the component
joblib.numpy_pickle::NumpyArrayWrapper().read_array(). NOTE: this is
disputed by the supplier because NumpyArrayWrapper is only used during
caching of trusted content.

AI Score

6.9

Confidence

High

EPSS

0

Percentile

9.0%