Vulnerability Description
DeepJavaLibrary(DJL) is an Engine-Agnostic Deep Learning Framework in Java. DJL versions 0.1.0 through 0.27.0 do not prevent absolute path archived artifacts from inserting archived files directly into the system, overwriting system files. This is fixed in DJL 0.28.0 and patched in DJL Large Model Inference containers version 0.27.0. Users are advised to upgrade.
CVSS Score
CRITICAL
Related Weaknesses (CWE)
References
- https://github.com/deepjavalibrary/djl/releases/tag/v0.28.0
- https://github.com/deepjavalibrary/djl/security/advisories/GHSA-w877-jfw7-46rj
- https://github.com/deepjavalibrary/djl/releases/tag/v0.28.0
- https://github.com/deepjavalibrary/djl/security/advisories/GHSA-w877-jfw7-46rj
FAQ
What is CVE-2024-37902?
CVE-2024-37902 is a vulnerability with a CVSS score of 10.0 (CRITICAL). DeepJavaLibrary(DJL) is an Engine-Agnostic Deep Learning Framework in Java. DJL versions 0.1.0 through 0.27.0 do not prevent absolute path archived artifacts from inserting archived files directly int...
How severe is CVE-2024-37902?
CVE-2024-37902 has been rated CRITICAL with a CVSS base score of 10.0/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2024-37902?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.