Risk Scores
CVSS v3.1
7.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P
EPSS Score
0.26%
49.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| fedoraproject | fedora | 36, 37 |
| PyPI | joblib | 0 |
| fedoraproject | fedora | 36, 37 |
| joblib_project | joblib | 0 |
| n/a | joblib | 0, unspecified |
| joblib_project | joblib | 0 |
| debian | debian_linux | 10.0 |
| debian | debian_linux | 10.0 |
Timeline
- Sep 26, 2022 EPSS Score
- Sep 26, 2022 CVE Published
- Sep 27, 2022 EPSS Score
- Nov 9, 2022 EPSS Score
- Dec 23, 2022 EPSS Score
- Mar 7, 2023 EPSS Score
- Mar 21, 2023 EPSS Score
- May 4, 2023 EPSS Score
- Jun 17, 2023 EPSS Score
- Jul 31, 2023 EPSS Score
- Sep 13, 2023 EPSS Score
- Oct 27, 2023 EPSS Score
References
- https://security.snyk.io/vuln/SNYK-PYTHON-JOBLIB-3027033 url
- https://github.com/joblib/joblib/commit/b90f10efeb670a2cc877fb88ebb3f2019189e059 url
- https://github.com/joblib/joblib/issues/1128 url
- https://github.com/joblib/joblib/pull/1321 url
- FEDORA-2022-c0bfe37ae5 vendor-advisory
- FEDORA-2022-c83ce1c000 vendor-advisory
- [debian-lts-announce] 20221117 [SECURITY] [DLA 3193-1] joblib security update mailing-list
- [debian-lts-announce] 20230330 [SECURITY] [DLA 3193-2] joblib security update mailing-list
- GLSA-202401-01 vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-21797 advisory
- https://github.com/joblib/joblib/pull/1327 url
- https://github.com/joblib/joblib/pull/1352 url
- https://github.com/joblib/joblib/commit/6638b9e9711ad1ebbf6dd95aa7cee0dca9897b42 url
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MJ5XTJS6OKJRRVXWFN5J67K3BYPEOBDF url
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BVOMMW37OXZWU2EV5ONAAS462IQEHZOF url
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MJ5XTJS6OKJRRVXWFN5J67K3BYPEOBDF url
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BVOMMW37OXZWU2EV5ONAAS462IQEHZOF url
- https://github.com/pypa/advisory-database/tree/main/vulns/joblib/PYSEC-2022-288.yaml url
- https://github.com/joblib/joblib package