Skip to content
DeepSpeedGHSA-8cp5-3rf8-8gfh

DeepSpeed Remote Code Execution Vulnerability

High8.4CVE-2024-43497 · Published Oct 8, 2024 · updated Oct 18, 2024

GitHub advisory

Affected versions

PackageAffectedFixed in
deepspeed
PyPI
< 0.15.10.15.1
Details and references

DeepSpeed Remote Code Execution Vulnerability

CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-77
Also known as
CVE-2024-43497, PYSEC-2024-109

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.