1.17.0
4 years ago
9 days ago
Known vulnerabilities in the clearml package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
clearml is a ClearML - Auto-Magical Experiment Manager, Version Control, and MLOps for AI Affected versions of this package are vulnerable to Deserialization of Untrusted Data. An attacker can execute arbitrary code on an end user's system by uploading a malicious pickle file as an artifact that triggers the deserialization flaw when a user calls the How to fix Deserialization of Untrusted Data? Upgrade | [0.17.0,1.14.3rc0) |
clearml is a ClearML - Auto-Magical Experiment Manager, Version Control, and MLOps for AI Affected versions of this package are vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') inside the How to fix Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')? Upgrade | [,1.14.2) |