1.13.1
6 months ago
7 days ago
Known vulnerabilities in the sagemaker-serve package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
sagemaker-serve is a SageMaker Serve package for model serving and deployment Affected versions of this package are vulnerable to Improper Validation of Integrity Check Value in the Triton inference handler. An attacker can execute arbitrary code with the SageMaker execution role's IAM permissions by uploading a specially crafted model artifact payload to the S3 path used by the handler, provided they have authenticated S3 write access to that location. How to fix Improper Validation of Integrity Check Value? Upgrade | [,1.8.0) |
sagemaker-serve is a SageMaker Serve package for model serving and deployment Affected versions of this package are vulnerable to Cleartext Storage of Sensitive Information in the How to fix Cleartext Storage of Sensitive Information? Upgrade | [,1.8.0) |