Advisory Database
  • Advisories
  • Dependency Scanning
  1. maven
  2. ›
  3. org.deeplearning4j/platform-tests
  4. ›
  5. CVE-2022-36022

CVE-2022-36022: Use of unclaimed s3 bucket in tests and examples

November 10, 2022 (updated November 15, 2022)

Deeplearning4J is a suite of tools for deploying and training deep learning models using the JVM. Packages org.deeplearning4j:dl4j-examples and org.deeplearning4j:platform-tests through version 1.0.0-M2.1 may use some unclaimed S3 buckets in tests in examples. This is likely affect people who use some older NLP examples that reference an old S3 bucket. The problem has been patched. Users should upgrade to snapshots as Deeplearning4J plan to publish a release with the fix at a later date. As a workaround, download a word2vec google news vector from a new source using git lfs from here.

References

  • github.com/advisories/GHSA-rc39-g977-687w
  • github.com/deeplearning4j/deeplearning4j/security/advisories/GHSA-rc39-g977-687w
  • github.com/eclipse/deeplearning4j/security/advisories/GHSA-rc39-g977-687w
  • github.com/mmihaltz/word2vec-GoogleNews-vectors
  • nvd.nist.gov/vuln/detail/CVE-2022-36022

Code Behaviors & Features

Detect and mitigate CVE-2022-36022 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 1.0.0

Fixed versions

  • 1.0.0

Solution

Upgrade to version 1.0.0 or above.

Impact 5.3 MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Learn more about CVSS

Weakness

  • CWE-330: Use of Insufficiently Random Values

Source file

maven/org.deeplearning4j/platform-tests/CVE-2022-36022.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:16:09 +0000.