GHSA-rc39-g977-687w

Suggest an improvement
Source
https://github.com/advisories/GHSA-rc39-g977-687w
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/11/GHSA-rc39-g977-687w/GHSA-rc39-g977-687w.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-rc39-g977-687w
Aliases
  • CVE-2022-36022
Published
2022-11-10T21:27:55Z
Modified
2023-11-08T04:09:57.933172Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N CVSS Calculator
Summary
Use of unclaimed s3 bucket in tests and examples
Details

Impact

People who use some older NLP examples that reference the old S3 bucket.

Patches

The problem has been patched. Upgrade to snapshots for now. A release will be published later to address this due to the vulnerability mostly being examples and 1 class in the actual code base.

Workarounds

Download a word2vec google news vector from a new source using git lfs

Database specific
{
    "nvd_published_at": "2022-11-10T18:15:00Z",
    "github_reviewed_at": "2022-11-10T21:27:55Z",
    "severity": "MODERATE",
    "github_reviewed": true,
    "cwe_ids": [
        "CWE-330",
        "CWE-344"
    ]
}
References

Affected packages

Maven / org.deeplearning4j:platform-tests

Package

Name
org.deeplearning4j:platform-tests
View open source insights on deps.dev
Purl
pkg:maven/org.deeplearning4j/platform-tests

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
1.0.0-M2.1

Maven / org.deeplearning4j:dl4j-examples

Package

Name
org.deeplearning4j:dl4j-examples
View open source insights on deps.dev
Purl
pkg:maven/org.deeplearning4j/dl4j-examples

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
1.0.0-M2.1