bigdl@2.4.0b20230902 vulnerabilities

Building Large-Scale AI Applications for Distributed Big Data

  • latest version

    2.4.0

  • latest non vulnerable version

  • first published

    7 years ago

  • latest version published

    1 years ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the bigdl package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Inadequate Encryption Strength

    bigdl is a Building Large-Scale AI Applications for Distributed Big Data

    Affected versions of this package are vulnerable to Inadequate Encryption Strength due to the usage of an insecure DES3 encryption algorithm.

    How to fix Inadequate Encryption Strength?

    Upgrade bigdl to version 2.4.0 or higher.

    [,2.4.0)
    • C
    Command Injection

    bigdl is a Building Large-Scale AI Applications for Distributed Big Data

    Affected versions of this package are vulnerable to Command Injection in pickle.load()

    How to fix Command Injection?

    Upgrade bigdl to version 2.4.0 or higher.

    [,2.4.0)