VulnerabilityModified
CVE-2022-21797
The package joblib from 0 and before 1.2.0 are vulnerable to Arbitrary Code Execution via the pre_dispatch flag in Parallel() class due to the eval() statement.
CRITICAL 9.8EPSS 2.10%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.10%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The package joblib from 0 and before 1.2.0 are vulnerable to Arbitrary Code Execution via the pre_dispatch flag in Parallel() class due to the eval() statement.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 2.10% probability · 81th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-94
- Affected
- joblib project/joblib · fedoraproject/fedora · debian/debian linux
- Source
- report@snyk.io
References
- https://github.com/joblib/joblib/commit/b90f10efeb670a2cc877fb88ebb3f2019189e059Patch, Third Party Advisory
- https://github.com/joblib/joblib/issues/1128Exploit, Issue Tracking, Third Party Advisory
- https://github.com/joblib/joblib/pull/1321Issue Tracking, Patch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/11/msg00020.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/03/msg00027.htmlMailing List, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BVOMMW37OXZWU2EV5ONAAS462IQEHZOF/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MJ5XTJS6OKJRRVXWFN5J67K3BYPEOBDF/
- https://security.gentoo.org/glsa/202401-01
- https://security.snyk.io/vuln/SNYK-PYTHON-JOBLIB-3027033Exploit, Issue Tracking, Patch, Third Party Advisory
- https://github.com/joblib/joblib/commit/b90f10efeb670a2cc877fb88ebb3f2019189e059Patch, Third Party Advisory
- https://github.com/joblib/joblib/issues/1128Exploit, Issue Tracking, Third Party Advisory
- https://github.com/joblib/joblib/pull/1321Issue Tracking, Patch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/11/msg00020.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/03/msg00027.htmlMailing List, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BVOMMW37OXZWU2EV5ONAAS462IQEHZOF/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MJ5XTJS6OKJRRVXWFN5J67K3BYPEOBDF/
- https://security.gentoo.org/glsa/202401-01
- https://security.snyk.io/vuln/SNYK-PYTHON-JOBLIB-3027033Exploit, Issue Tracking, Patch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.