← back
CVE-2022-21797highCWE-94

Arbitrary Code Execution

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 7.3epss 2.6%
exploitation probability
2.6%top 15% of all CVEs
observed exploitation
nono source reports it
The package joblib from 0 and before 1.2.0 are vulnerable to Arbitrary Code Execution via the pre_dispatch flag in Parallel() class due to the eval() statement.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P
Affected products
n/a · joblib