—
PYSEC-2022-288
Quick fix
PYSEC-2022-288 — joblib: upgrade to the fixed version with the command below.
pip install --upgrade 'joblib>=b90f10efeb670a2cc877fb88ebb3f2019189e059'Details
The package joblib from 0 and before 1.2.0 are vulnerable to Arbitrary Code Execution via the pre_dispatch flag in Parallel() class due to the eval() statement.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/joblib
Introduced in:
0Fixed in: b90f10efeb670a2cc877fb88ebb3f2019189e059Fix
pip install --upgrade 'joblib>=b90f10efeb670a2cc877fb88ebb3f2019189e059'References
- https://github.com/joblib/joblib/commit/b90f10efeb670a2cc877fb88ebb3f2019189e059[FIX]
- https://github.com/joblib/joblib/issues/1128[REPORT]
- https://github.com/joblib/joblib/pull/1321[WEB]
- https://security.snyk.io/vuln/SNYK-PYTHON-JOBLIB-3027033[WEB]
- https://github.com/advisories/GHSA-6hrg-qmvc-2xh8[ADVISORY]