DeepJavaLibrary(DJL) is an Engine-Agnostic Deep Learning Framework in Java. DJL versions 0.1.0 through 0.27.0 do not prevent absolute path archived artifacts from inserting archived files directly into the system, overwriting system files. This is fixed in DJL 0.28.0 and patched in DJL Large Model Inference containers version 0.27.0. Users are advised to upgrade.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-2188 | DeepJavaLibrary(DJL) is an Engine-Agnostic Deep Learning Framework in Java. DJL versions 0.1.0 through 0.27.0 do not prevent absolute path archived artifacts from inserting archived files directly into the system, overwriting system files. This is fixed in DJL 0.28.0 and patched in DJL Large Model Inference containers version 0.27.0. Users are advised to upgrade. |
Github GHSA |
GHSA-w877-jfw7-46rj | DeepJavaLibrary API absolute path traversal |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-02T04:04:23.429Z
Reserved: 2024-06-10T19:54:41.362Z
Link: CVE-2024-37902
Updated: 2024-08-02T04:04:23.429Z
Status : Awaiting Analysis
Published: 2024-06-17T20:15:14.463
Modified: 2024-11-21T09:24:30.200
Link: CVE-2024-37902
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA