CVE-2020-13092

Source
https://nvd.nist.gov/vuln/detail/CVE-2020-13092
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-13092.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2020-13092
Aliases
Withdrawn
2020-05-18T11:16:54Z
Published
2020-05-15T19:15:12Z
Modified
2024-10-12T04:46:46.399812Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

scikit-learn (aka sklearn) through 0.23.0 can unserialize and execute commands from an untrusted file that is passed to the joblib.load() function, if reduce makes an os.system call. NOTE: third parties dispute this issue because the joblib.load() function is documented as unsafe and it is the user's responsibility to use the function in a secure manner

References

Affected packages

Debian:11 / scikit-learn

Package

Name
scikit-learn
Purl
pkg:deb/debian/scikit-learn?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*

0.23.2-5

1.*

1.0.1-1
1.0.1-1.1
1.0.2-1
1.1.1-1
1.1.1-2
1.1.2+dfsg-1
1.1.2+dfsg-2
1.1.2+dfsg-3
1.1.2+dfsg-4
1.1.2+dfsg-5~exp1
1.1.2+dfsg-5
1.1.2+dfsg-6
1.1.2+dfsg-7
1.1.2+dfsg-8
1.1.2+dfsg-91
1.1.2+dfsg-92
1.2.1+dfsg-0exp1
1.2.1+dfsg-1
1.4.1.post1+dfsg-1
1.4.2+dfsg-1
1.4.2+dfsg-2
1.4.2+dfsg-3
1.4.2+dfsg-4
1.4.2+dfsg-5
1.4.2+dfsg-6

Ecosystem specific

{
    "urgency": "unimportant"
}

Debian:12 / scikit-learn

Package

Name
scikit-learn
Purl
pkg:deb/debian/scikit-learn?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.2.1+dfsg-1
1.4.1.post1+dfsg-1
1.4.2+dfsg-1
1.4.2+dfsg-2
1.4.2+dfsg-3
1.4.2+dfsg-4
1.4.2+dfsg-5
1.4.2+dfsg-6

Ecosystem specific

{
    "urgency": "unimportant"
}

Debian:13 / scikit-learn

Package

Name
scikit-learn
Purl
pkg:deb/debian/scikit-learn?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.2.1+dfsg-1
1.4.1.post1+dfsg-1
1.4.2+dfsg-1
1.4.2+dfsg-2
1.4.2+dfsg-3
1.4.2+dfsg-4
1.4.2+dfsg-5
1.4.2+dfsg-6

Ecosystem specific

{
    "urgency": "unimportant"
}

Git / github.com/scikit-learn/scikit-learn

Affected ranges

Type
GIT
Repo
https://github.com/scikit-learn/scikit-learn
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected

Affected versions

0.*

0.1
0.1-beta
0.10-branching
0.11-beta
0.11-branching
0.12-branching
0.13-branching
0.15-branching
0.15.0b1
0.16-branching
0.17-branching
0.19-branching
0.2
0.2-beta
0.23.0
0.23.0rc1
0.3
0.4
0.5
0.5.rc
0.5.rc2
0.5.rc3
0.7-branching
0.8-branching
0.9-branching

Other

sprint01