GHSA-2vj5-px25-gjrp
Dashboard / Vulnerabilities / GHSA-2vj5-px25-gjrp
GHSA-2vj5-px25-gjrp
Summary: pytorch-lightning is vulnerable to Deserialization of Untrusted Data
Details: pytorch-lightning is vulnerable to Deserialization of Untrusted Data.
References: https://nvd.nist.gov/vuln/detail/CVE-2021-4118, https://github.com/PyTorchLightning/pytorch-lightning/issues/11045, https://github.com/PyTorchLightning/pytorch-lightning/pull/11099, https://github.com/pytorchlightning/pytorch-lightning/commit/62f1e82e032eb16565e676d39e0db0cac7e34ace, https://github.com/PyTorchLightning/pytorch-lightning/releases/tag/1.6.0, https://github.com/advisories/GHSA-2vj5-px25-gjrp, https://github.com/pypa/advisory-database/tree/main/vulns/pytorch-lightning/PYSEC-2021-874.yaml, https://github.com/pytorchlightning/pytorch-lightning, https://huntr.dev/bounties/31832f0c-e5bb-4552-a12c-542f81f111e6
Affected packages
Package
Name: pytorch-lightning
Purl: pkg:pypi/pytorch-lightning
Affected ranges
Type: ECOSYSTEM
Events:
