2 known bugs in joblib, with affected versions, fixes and workarounds. Sourced from upstream issue trackers.
| Severity | Affected | Fixed in | Title | Status | Source |
|---|---|---|---|---|---|
| medium | any | b90f10efeb670a2cc877fb88ebb3f2019189e059 | PYSEC-2022-288: advisory The package joblib from 0 and before 1.2.0 are vulnerable to Arbitrary Code Execution via the pre_dispatch flag in Parallel() class due to the eval() statement. | fixed | osv:PYSEC-2022-288 |
| critical | any | 1.2.0 | joblib vulnerable to arbitrary code execution The package joblib from 0 and before 1.2.0 is vulnerable to Arbitrary Code Execution via the `pre_dispatch` flag in `Parallel()` class due to the `eval()` statement. | fixed | osv:GHSA-6hrg-qmvc-2xh8 |
Get this data programmatically \u2014 free, no authentication.
curl https://depscope.dev/api/bugs/pypi/joblib