ms-swift@4.1.3

Swift: Scalable lightWeight Infrastructure for Fine-Tuning

Direct Vulnerabilities

Known vulnerabilities in the ms-swift package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • M
Use of Weak Hash

ms-swift is a Swift: Scalable lightWeight Infrastructure for Fine-Tuning

Affected versions of this package are vulnerable to Use of Weak Hash in the Template._save_pil_image() function in swift/template/base.py. An attacker can exploit a weakness in cache key integrity to tamper with the resolved image from a given hash. Different images with identical raw bytes and different dimensions may have the same hash, which can be used to cause the wrong image to be returned by a hash lookup.

How to fix Use of Weak Hash?

A fix was pushed into the master branch but not yet published.

[0,)