The package joblib from 0 and prior to 1.2.0 are vulnerable to Arbitrary Code Execution via the pre_dispatch flag in Parallel() class due to the eval() statement.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
joblib project joblib |
||
fedoraproject fedora 36 |
||
fedoraproject fedora 37 |
||
debian debian linux 10.0 |