Incorrect Access Control Affecting dask package, versions [0,2021.10.0)


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
2.23% (90th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Incorrect Access Control vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-PYTHON-DASK-1767103
  • published26 Oct 2021
  • disclosed26 Oct 2021
  • creditUnknown

Introduced: 26 Oct 2021

CVE-2021-42343  (opens in a new tab)
CWE-284  (opens in a new tab)

How to fix?

Upgrade dask to version 2021.10.0 or higher.

Overview

dask is a Parallel PyData with Task Scheduling

Affected versions of this package are vulnerable to Incorrect Access Control. Single machine Dask clusters started with dask.distributed.LocalCluster or dask.distributed.Client (which defaults to using LocalCluster) would mistakenly configure their respective Dask workers to listen on external interfaces rather than only on localhost. A Dask cluster created using this method (when running on a machine that has an applicable port exposed) could be used by an attacker to achieve remote code execution.

CVSS Scores

version 3.1