-
Notifications
You must be signed in to change notification settings - Fork 3.8k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Vulnerabilities CVE-2024-43598 & sonatype-2024-013191 found in the latest v4.5.0 #6759
Comments
Thanks for using LightGBM. Please:
A fix has been merged, we will try to do a release in the next few weeks. The vulnerability only affects distributed (multi-machine) training, so if you don't do that you can safely ignore it. |
Hi @jameslamb thanks a lot for the quick response and the fix. And my apologies for this confusion. Regards, |
Please release it so the community can use the fix! |
@jameslamb could you please provide ETA of the next release (which will contain the mentioned fix)? Thanks |
We will do a release when we can. I do not have an ETA. We understand. |
Description
Hello,
Our Sonatype security scanner has detected CVE sonatype-2024-013191 and https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43598 in the latest version of the lightgbm– v4.5.0 (and in the current version we use for our python services - v4.0.0).
Based on the Sonatype description, there is no non-vulnerable version available.
Could you please provide the necessary fix and release?
Thanks
The text was updated successfully, but these errors were encountered: