Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-32g6-mg92-ghm2

Опубликовано: 20 мар. 2025
Источник: github
Github: Прошло ревью
CVSS3: 5.9

Описание

SageMaker Workflow component allows possibility of MD5 hash collisions

A vulnerability in the SageMaker Workflow component of aws/sagemaker-python-sdk allows for the possibility of MD5 hash collisions in all versions. This can lead to workflows being inadvertently replaced due to the reuse of results from different configurations that produce the same MD5 hash. This issue can cause integrity problems within the pipeline, potentially leading to erroneous processing outcomes.

Пакеты

Наименование

sagemaker

pip
Затронутые версииВерсия исправления

< 2.237.3

2.237.3

EPSS

Процентиль: 17%
0.00053
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-328
CWE-440

Связанные уязвимости

CVSS3: 5.9
nvd
11 месяцев назад

A vulnerability in the SageMaker Workflow component of aws/sagemaker-python-sdk allows for the possibility of MD5 hash collisions in all versions. This can lead to workflows being inadvertently replaced due to the reuse of results from different configurations that produce the same MD5 hash. This issue can cause integrity problems within the pipeline, potentially leading to erroneous processing outcomes.

EPSS

Процентиль: 17%
0.00053
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-328
CWE-440