DeepJavaLibrary(DJL) is an Engine-Agnostic Deep Learning Framework in Java. DJL versions 0.1.0 through 0.27.0 do not prevent absolute path archived artifacts from inserting archived files directly into the system, overwriting system files. This is fixed in DJL 0.28.0 and patched in DJL Large Model Inference containers version 0.27.0. Users are advised to upgrade.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-06-17T19:25:21.831Z
Updated: 2024-08-02T04:04:23.429Z
Reserved: 2024-06-10T19:54:41.362Z
Link: CVE-2024-37902

Updated: 2024-08-02T04:04:23.429Z

Status : Awaiting Analysis
Published: 2024-06-17T20:15:14.463
Modified: 2024-11-21T09:24:30.200
Link: CVE-2024-37902

No data.