漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
FedML-AI FedML gRPC server grpc_server.py sendMessage deserialization
Vulnerability Description
A weakness has been identified in FedML-AI FedML up to 0.8.9. Affected is the function sendMessage of the file grpc_server.py of the component gRPC server. Executing a manipulation can lead to deserialization. The attack may be performed from remote. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Vulnerability Type
可信数据的反序列化
Vulnerability Title
FEDML 代码问题漏洞
Vulnerability Description
FEDML是TensorOpera开源的一个统一且可扩展的机器学习训练与部署库。 FedML 0.8.9及之前版本存在代码问题漏洞,该漏洞源于函数sendMessage存在反序列化问题。
CVSS Information
N/A
Vulnerability Type
N/A