The package joblib from 0 and before 1.2.0 are vulnerable to Arbitrary Code Execution via the pre_dispatch flag in Parallel() class due to the eval() statement.
| Software | From | Fixed in |
|---|---|---|
| fedoraproject / fedora | 36 | 36.x |
| fedoraproject / fedora | 37 | 37.x |
| debian / debian_linux | 10.0 | 10.0.x |
joblib
|
- | 1.2.0 |
| joblib_project / joblib | - | 1.1.1 |