Skip to content

Use of unclaimed s3 bucket in tests and examples

Low
eclipsewebmaster published GHSA-rc39-g977-687w Nov 10, 2022

Package

maven org.deeplearning4j:dl4j-examples (Maven)

Affected versions

<=1.0.0-M2.1

Patched versions

None
maven org.deeplearning4j:platform-tests (Maven)
<=1.0.0-M2.1
None

Description

Impact

People who use some older NLP examples that reference the old S3 bucket.

Patches

The problem has been patched. Upgrade to snapshots for now. A release will be published later to address this due to the vulnerability mostly being examples and 1 class in the actual code base.

Workarounds

Download a word2vec google news vector from a new source using git lfs from here: https://github.com/mmihaltz/word2vec-GoogleNews-vectors

References

For more information

If you have any questions or comments about this advisory:

Severity

Low

CVE ID

CVE-2022-36022

Weaknesses

No CWEs

Credits