VDB
Sign up
CRITICAL10.0

GHSA-w877-jfw7-46rj

DeepJavaLibrary API absolute path traversal

Quick fix

GHSA-w877-jfw7-46rj — ai.djl:api: upgrade to the fixed version with the command below.

# pom.xml: bump <version>0.28.0</version> for ai.djl:api

Details

## Summary

DeepJavaLibrary(DJL) versions 0.1.0 through 0.27.0 do not prevent absolute path archived artifacts from inserting archived files directly into the system, overwriting system files. This is fixed in DJL 0.28.0 and patched in DJL Large Model Inference containers 0.27.0.

**Impacted versions: 0.1.0 through 0.27.0**

## Patches

Patched Deep Learning Containers: [v1.1-djl-0.27.0-inf-cpu-full](https://github.com/aws/deep-learning-containers/releases/tag/v1.1-djl-0.27.0-inf-cpu-full) [v1.4-djl-0.27.0-inf-ds-0.12.6](https://github.com/aws/deep-learning-containers/releases/tag/v1.4-djl-0.27.0-inf-ds-0.12.6) [v1.4-djl-0.27.0-inf-trt-0.8.0](https://github.com/aws/deep-learning-containers/releases/tag/v1.4-djl-0.27.0-inf-trt-0.8.0) [v1.3-djl-0.27.0-inf-neuronx-sdk2.18.1](https://github.com/aws/deep-learning-containers/releases/tag/v1.3-djl-0.27.0-inf-neuronx-sdk2.18.1)

Patched Library: [v0.28.0](https://github.com/deepjavalibrary/djl/releases/tag/v0.28.0)

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/ai.djl:api
Introduced in: 0.1.0Fixed in: 0.28.0
Fix# pom.xml: bump <version>0.28.0</version> for ai.djl:api

References