HIGH 7.8
PYSEC-2023-301
상세
Deserialization of Untrusted Data in GitHub repository huggingface/transformers prior to 4.36.
이 버전이 영향받나요?
사용 중인 패키지 버전을 입력하면 즉시 평가합니다.
영향 패키지
PyPI / transformers
최초 영향 버전:
0 수정 버전: 1d63b0ec361e7a38f1339385e8a5a855085532ce 수정
pip install --upgrade 'transformers>=1d63b0ec361e7a38f1339385e8a5a855085532ce' 참고
- https://huntr.com/bounties/e1a3e548-e53a-48df-b708-9ee62140963c [EVIDENCE]
- https://huntr.com/bounties/e1a3e548-e53a-48df-b708-9ee62140963c [FIX]
- https://huntr.com/bounties/e1a3e548-e53a-48df-b708-9ee62140963c [WEB]
- https://github.com/huggingface/transformers/commit/1d63b0ec361e7a38f1339385e8a5a855085532ce [FIX]
- https://github.com/advisories/GHSA-v68g-wm8c-6x7j [ADVISORY]