Race Condition Affecting spark-nlp package, versions [,3.4.0)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Race Condition vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-PYTHON-SPARKNLP-5818270
  • published3 Aug 2023
  • disclosed1 Aug 2023
  • creditUnknown

Introduced: 1 Aug 2023

CVE NOT AVAILABLE CWE-362  (opens in a new tab)

How to fix?

Upgrade spark-nlp to version 3.4.0 or higher.

Overview

spark-nlp is a John Snow Labs Spark NLP is a natural language processing library built on top of Apache Spark ML. It provides simple, performant & accurate NLP annotations for machine learning pipelines, that scale easily in a distributed environment.

Affected versions of this package are vulnerable to Race Condition when the get session is called as many times as the number of cores on the Driver at the same time and loading the model many times

References

CVSS Base Scores

version 3.1