Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hq6h-q7pr-4qqv

Опубликовано: 14 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 2.3
CVSS3: 3.1

Описание

A security vulnerability has been detected in wandb 0.25.2.dev1. Affected is the function ArtifactManifestEntry.download in the library wandb/sdk/lib/hashutil.py of the component Artifact Integrity Validation. The manipulation leads to use of weak hash. The attack may be initiated remotely. A high degree of complexity is needed for the attack. The exploitability is told to be difficult. The pull request to fix this issue awaits acceptance.

A security vulnerability has been detected in wandb 0.25.2.dev1. Affected is the function ArtifactManifestEntry.download in the library wandb/sdk/lib/hashutil.py of the component Artifact Integrity Validation. The manipulation leads to use of weak hash. The attack may be initiated remotely. A high degree of complexity is needed for the attack. The exploitability is told to be difficult. The pull request to fix this issue awaits acceptance.

EPSS

Процентиль: 5%
0.00151
Низкий

2.3 Low

CVSS4

3.1 Low

CVSS3

Дефекты

CWE-327

Связанные уязвимости

CVSS3: 3.1
redhat
около 1 месяца назад

A security vulnerability has been detected in wandb 0.25.2.dev1. Affected is the function ArtifactManifestEntry.download in the library wandb/sdk/lib/hashutil.py of the component Artifact Integrity Validation. The manipulation leads to use of weak hash. The attack may be initiated remotely. A high degree of complexity is needed for the attack. The exploitability is told to be difficult. The pull request to fix this issue awaits acceptance.

CVSS3: 3.1
nvd
около 1 месяца назад

A security vulnerability has been detected in wandb 0.25.2.dev1. Affected is the function ArtifactManifestEntry.download in the library wandb/sdk/lib/hashutil.py of the component Artifact Integrity Validation. The manipulation leads to use of weak hash. The attack may be initiated remotely. A high degree of complexity is needed for the attack. The exploitability is told to be difficult. The pull request to fix this issue awaits acceptance.

EPSS

Процентиль: 5%
0.00151
Низкий

2.3 Low

CVSS4

3.1 Low

CVSS3

Дефекты

CWE-327