First published: Thu Nov 10 2022(Updated: )
Deeplearning4J is a suite of tools for deploying and training deep learning models using the JVM. Packages org.deeplearning4j:dl4j-examples and org.deeplearning4j:platform-tests through version 1.0.0-M2.1 may use some unclaimed S3 buckets in tests in examples. This is likely affect people who use some older NLP examples that reference an old S3 bucket. The problem has been patched. Users should upgrade to snapshots as Deeplearning4J plan to publish a release with the fix at a later date. As a workaround, download a word2vec google news vector from a new source using git lfs from here.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Eclipse Deeplearning4j | <1.0.0 | |
Eclipse Deeplearning4j | =1.0.0-beta5 | |
Eclipse Deeplearning4j | =1.0.0-beta6 | |
Eclipse Deeplearning4j | =1.0.0-beta7 | |
Eclipse Deeplearning4j | =1.0.0-milestone1 | |
Eclipse Deeplearning4j | =1.0.0-milestone1.1 | |
Eclipse Deeplearning4j | =1.0.0-milestone2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-36022 is a vulnerability in Deeplearning4J that allows unclaimed S3 buckets to be used in tests in examples.
Deeplearning4J versions up to and including 1.0.0-M2.1 are affected by CVE-2022-36022.
CVE-2022-36022 may affect users who use the org.deeplearning4j:dl4j-examples and org.deeplearning4j:platform-tests packages in Deeplearning4J.
CVE-2022-36022 has a severity rating of medium with a CVSS score of 5.3.
To fix CVE-2022-36022, upgrade to a version of Deeplearning4J that is not affected, such as version 1.0.0 or later.