CVE-2022-45907

Source
https://nvd.nist.gov/vuln/detail/CVE-2022-45907
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-45907.json
Aliases
Published
2022-11-26T02:15:10Z
Modified
2023-12-06T01:02:42.829739Z
Details

In PyTorch before trunk/89695, torch.jit.annotations.parsetypeline can cause arbitrary code execution because eval is used unsafely.

References

Affected packages

Git / github.com/pytorch/pytorch

Affected ranges

Type
GIT
Repo
https://github.com/pytorch/pytorch
Events
Introduced
0The exact introduced commit is unknown
Fixed

Affected versions

Other

ciflow/libtorch/73011
ciflow/periodic/054a2fd
ciflow/periodic/2a6d37d
ciflow/periodic/317eeb8
ciflow/periodic/3c32
ciflow/periodic/74537
ciflow/periodic/78062
ciflow/periodic/78231
ciflow/periodic/78877
ciflow/periodic/79280
ciflow/periodic/79533
ciflow/periodic/79557
ciflow/periodic/79617
ciflow/periodic/79621
ciflow/periodic/79625
ciflow/periodic/79626
ciflow/periodic/79663
ciflow/periodic/79667
ciflow/periodic/79675
ciflow/periodic/csl/test87519
ciflow/periodic/csltest88275
ciflow/periodic/csltest88761
ciflow/periodic/sha-ec5b83
ciflow/trunk/78062
ciflow/trunk/79280
ciflow/trunk/85988
ciflow/trunk/86779
ciflow/trunk/87216
ciflow/trunk/87772
malfet/tag-2ef5611
malfet/tag-317b1a0
malfet/tag-ec6f767
nightly-binary

v0.*

v0.1.1
v0.1.10
v0.1.11
v0.1.2
v0.1.3
v0.1.4
v0.1.5
v0.1.6
v0.1.7
v0.1.8
v0.1.9

v1.*

v1.0.0a0
v1.0rc0
v1.0rc1
v1.1.0a0
v1.2.0a0
v1.3.0a0
v1.4.0a0
v1.8.0-rc1