The clustered setup of Apache MXNet allows users to specify which IP address and port the scheduler will listen on via the DMLC_PS_ROOT_URI and DMLC_PS_ROOT_PORT env variables. In versions older than 1.0.0, however, the MXNet framework will listen on 0.0.0.0 rather than user specified DMLC_PS_ROOT_URI once a scheduler node is initialized. This exposes the instance running MXNet to any attackers reachable via the interface they didn't expect to be listening on. For example: If a user wants to run a clustered setup locally, they may specify to run on 127.0.0.1. But since MXNet will listen on 0.0.0.0, it makes the port accessible on all network interfaces.
{
"cpe": "cpe:2.3:a:apache:mxnet:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "1.0.0"
}
],
"source": "CPE_RANGE"
}
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-1281.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"120897539249144181966431496770661025315",
"299990389390380498689687703070480517642",
"241052016591881057603990671576294435298",
"173106795815000665197339335555416545990"
],
"threshold": 0.9
},
"id": "CVE-2018-1281-65bc9758",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/dmlc/ps-lite/commit/4be817e8b03e7e92517e91f2dfcc50865e91c6ea",
"target": {
"file": "src/zmq_van.h"
}
}
]
"2026-08-27T08:15:25Z"