bigdl@2.3.0b20230328 vulnerabilities

Building Large-Scale AI Applications for Distributed Big Data

  • latest version

    2.4.0

  • latest non vulnerable version

  • first published

    7 years ago

  • latest version published

    1 years ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the bigdl package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Inadequate Encryption Strength

    bigdl is a Building Large-Scale AI Applications for Distributed Big Data

    Affected versions of this package are vulnerable to Inadequate Encryption Strength due to the usage of an insecure DES3 encryption algorithm.

    How to fix Inadequate Encryption Strength?

    Upgrade bigdl to version 2.4.0 or higher.

    [,2.4.0)
    • C
    Command Injection

    bigdl is a Building Large-Scale AI Applications for Distributed Big Data

    Affected versions of this package are vulnerable to Command Injection in pickle.load()

    How to fix Command Injection?

    Upgrade bigdl to version 2.4.0 or higher.

    [,2.4.0)
    • M
    Deserialization of Untrusted Data

    bigdl is a Building Large-Scale AI Applications for Distributed Big Data

    Affected versions of this package are vulnerable to Deserialization of Untrusted Data via the 'dlib' library, in File.scala.

    How to fix Deserialization of Untrusted Data?

    Upgrade bigdl to version 2.3.0 or higher.

    [,2.3.0)
    • M
    Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')

    bigdl is a Building Large-Scale AI Applications for Distributed Big Data

    Affected versions of this package are vulnerable to Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') via the 'dlib' library, in ModelBroadcast.scala.

    How to fix Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')?

    Upgrade bigdl to version 2.3.0 or higher.

    [,2.3.0)
    • M
    SQL Injection

    bigdl is a Building Large-Scale AI Applications for Distributed Big Data

    Affected versions of this package are vulnerable to SQL Injection due to users having direct access to file python/benchmark/run.py, which allows them to pass arguments to change the SQL contents.

    How to fix SQL Injection?

    Upgrade bigdl to version 2.3.0 or higher.

    [,2.3.0)
    • M
    Cross-site Scripting (XSS)

    bigdl is a Building Large-Scale AI Applications for Distributed Big Data

    Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via the 'dlib' library, in TorchFile.scala.

    How to fix Cross-site Scripting (XSS)?

    Upgrade bigdl to version 2.3.0 or higher.

    [,2.3.0)