mindspore@1.8.1 vulnerabilities

MindSpore is a new open source deep learning training/inference framework that could be used for mobile, edge and cloud scenarios.

Direct Vulnerabilities

Known vulnerabilities in the mindspore package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • M
Out-of-Bounds

mindspore is a MindSpore is an open source deep learning training/inference framework that could be used for mobile, edge and cloud scenarios.

Affected versions of this package are vulnerable to Out-of-Bounds via the JsonHelper::UpdateArray function of the mindspore/ccsrc/minddata/dataset/util/json_helper.cc file.

How to fix Out-of-Bounds?

A fix was pushed into the master branch but not yet published.

[0,)