CVE-2021-4118: Deserialization of Untrusted Data in pytorchlightning/pytorch-lightning
Published Dec 23, 2021
·Updated
pytorch-lightning is vulnerable to Deserialization of Untrusted Data
Affected Software
3 affected componentsFixes available
pip/pytorch-lightning<1.6.0
1.6.0
Lightningai Pytorch Lightning Python<1.6.0
pytorchlightning Pytorch Lightning Python<1.6.0
Remediation
Event History
Dec 23, 2021
CVE Published
via MITRE·05:15 PM
Data Sourced
via MITRE·05:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Jan 6, 2022
Advisory Published
via GitHub·11:58 PM
Frequently Asked Questions
1
What is the severity of CVE-2021-4118?
CVE-2021-4118 is classified as a medium-severity vulnerability due to its impact on deserialization of untrusted data.
2
How do I fix CVE-2021-4118?
To fix CVE-2021-4118, upgrade pytorch-lightning to version 1.6.0 or later.
3
What is the impact of CVE-2021-4118?
The impact of CVE-2021-4118 involves potential remote code execution through the deserialization process.
4
Which versions of pytorch-lightning are affected by CVE-2021-4118?
CVE-2021-4118 affects all versions of pytorch-lightning prior to 1.6.0.
5
Is CVE-2021-4118 specific to any programming language?
CVE-2021-4118 specifically affects the Python implementation of pytorch-lightning.