An incomplete string comparison in the numpy.core component in NumPy before 1.22.0 allows attackers to trigger slightly incorrect copying by constructing specific string objects. NOTE: the vendor states that this reported code behavior is "completely harmless."
| Software | From | Fixed in |
|---|---|---|
| numpy / numpy | - | 1.22.0 |
| oracle / communications_cloud_native_core_policy | 22.1.3 | 22.1.3.x |
numpy
|
- | 1.22 |