Critical severity10.0OSV Advisory· Published Jun 17, 2024· Updated Apr 15, 2026
CVE-2024-37902
CVE-2024-37902
Description
DeepJavaLibrary(DJL) is an Engine-Agnostic Deep Learning Framework in Java. DJL versions 0.1.0 through 0.27.0 do not prevent absolute path archived artifacts from inserting archived files directly into the system, overwriting system files. This is fixed in DJL 0.28.0 and patched in DJL Large Model Inference containers version 0.27.0. Users are advised to upgrade.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
ai.djl:apiMaven | >= 0.1.0, < 0.28.0 | 0.28.0 |
Affected products
126- Range: v0.1.0, v0.2.0
- osv-coords125 versionspkg:apk/chainguard/opensearch-2pkg:apk/chainguard/opensearch-2-alertingpkg:apk/chainguard/opensearch-2-analysis-icupkg:apk/chainguard/opensearch-2-analysis-kuromojipkg:apk/chainguard/opensearch-2-analysis-noripkg:apk/chainguard/opensearch-2-analysis-phoneticpkg:apk/chainguard/opensearch-2-analysis-smartcnpkg:apk/chainguard/opensearch-2-analysis-stempelpkg:apk/chainguard/opensearch-2-analysis-ukrainianpkg:apk/chainguard/opensearch-2-anomaly-detectionpkg:apk/chainguard/opensearch-2-asynchronous-searchpkg:apk/chainguard/opensearch-2-cross-cluster-replicationpkg:apk/chainguard/opensearch-2-crypto-kmspkg:apk/chainguard/opensearch-2-custom-codecspkg:apk/chainguard/opensearch-2-discovery-azure-classicpkg:apk/chainguard/opensearch-2-discovery-ec2pkg:apk/chainguard/opensearch-2-discovery-gcepkg:apk/chainguard/opensearch-2-entrypoint-compatpkg:apk/chainguard/opensearch-2-geospatialpkg:apk/chainguard/opensearch-2-identity-shiropkg:apk/chainguard/opensearch-2-index-managementpkg:apk/chainguard/opensearch-2-ingest-attachmentpkg:apk/chainguard/opensearch-2-job-schedulerpkg:apk/chainguard/opensearch-2-jre-bcfipspkg:apk/chainguard/opensearch-2-jre-bcfips-alertingpkg:apk/chainguard/opensearch-2-jre-bcfips-analysis-icupkg:apk/chainguard/opensearch-2-jre-bcfips-analysis-kuromojipkg:apk/chainguard/opensearch-2-jre-bcfips-analysis-noripkg:apk/chainguard/opensearch-2-jre-bcfips-analysis-phoneticpkg:apk/chainguard/opensearch-2-jre-bcfips-analysis-smartcnpkg:apk/chainguard/opensearch-2-jre-bcfips-analysis-stempelpkg:apk/chainguard/opensearch-2-jre-bcfips-analysis-ukrainianpkg:apk/chainguard/opensearch-2-jre-bcfips-anomaly-detectionpkg:apk/chainguard/opensearch-2-jre-bcfips-asynchronous-searchpkg:apk/chainguard/opensearch-2-jre-bcfips-cross-cluster-replicationpkg:apk/chainguard/opensearch-2-jre-bcfips-crypto-kmspkg:apk/chainguard/opensearch-2-jre-bcfips-custom-codecspkg:apk/chainguard/opensearch-2-jre-bcfips-discovery-azure-classicpkg:apk/chainguard/opensearch-2-jre-bcfips-discovery-ec2pkg:apk/chainguard/opensearch-2-jre-bcfips-discovery-gcepkg:apk/chainguard/opensearch-2-jre-bcfips-geospatialpkg:apk/chainguard/opensearch-2-jre-bcfips-identity-shiropkg:apk/chainguard/opensearch-2-jre-bcfips-index-managementpkg:apk/chainguard/opensearch-2-jre-bcfips-ingest-attachmentpkg:apk/chainguard/opensearch-2-jre-bcfips-job-schedulerpkg:apk/chainguard/opensearch-2-jre-bcfips-k-nnpkg:apk/chainguard/opensearch-2-jre-bcfips-mapper-annotated-textpkg:apk/chainguard/opensearch-2-jre-bcfips-mapper-murmur3pkg:apk/chainguard/opensearch-2-jre-bcfips-mapper-sizepkg:apk/chainguard/opensearch-2-jre-bcfips-ml-commonspkg:apk/chainguard/opensearch-2-jre-bcfips-neural-searchpkg:apk/chainguard/opensearch-2-jre-bcfips-notificationspkg:apk/chainguard/opensearch-2-jre-bcfips-observabilitypkg:apk/chainguard/opensearch-2-jre-bcfips-performance-analyzerpkg:apk/chainguard/opensearch-2-jre-bcfips-reportingpkg:apk/chainguard/opensearch-2-jre-bcfips-repository-azurepkg:apk/chainguard/opensearch-2-jre-bcfips-repository-gcspkg:apk/chainguard/opensearch-2-jre-bcfips-repository-s3pkg:apk/chainguard/opensearch-2-jre-bcfips-securitypkg:apk/chainguard/opensearch-2-jre-bcfips-security-analyticspkg:apk/chainguard/opensearch-2-jre-bcfips-sqlpkg:apk/chainguard/opensearch-2-jre-bcfips-store-smbpkg:apk/chainguard/opensearch-2-jre-bcfips-telemetry-otelpkg:apk/chainguard/opensearch-2-jre-bcfips-transport-niopkg:apk/chainguard/opensearch-2-k-nnpkg:apk/chainguard/opensearch-2-mapper-annotated-textpkg:apk/chainguard/opensearch-2-mapper-murmur3pkg:apk/chainguard/opensearch-2-mapper-sizepkg:apk/chainguard/opensearch-2-ml-commonspkg:apk/chainguard/opensearch-2-neural-searchpkg:apk/chainguard/opensearch-2-notificationspkg:apk/chainguard/opensearch-2-observabilitypkg:apk/chainguard/opensearch-2-performance-analyzerpkg:apk/chainguard/opensearch-2-reportingpkg:apk/chainguard/opensearch-2-repository-azurepkg:apk/chainguard/opensearch-2-repository-gcspkg:apk/chainguard/opensearch-2-repository-s3pkg:apk/chainguard/opensearch-2-securitypkg:apk/chainguard/opensearch-2-security-analyticspkg:apk/chainguard/opensearch-2-sqlpkg:apk/chainguard/opensearch-2-store-smbpkg:apk/chainguard/opensearch-2-telemetry-otelpkg:apk/chainguard/opensearch-2-transport-niopkg:apk/wolfi/opensearch-2pkg:apk/wolfi/opensearch-2-alertingpkg:apk/wolfi/opensearch-2-analysis-icupkg:apk/wolfi/opensearch-2-analysis-kuromojipkg:apk/wolfi/opensearch-2-analysis-noripkg:apk/wolfi/opensearch-2-analysis-phoneticpkg:apk/wolfi/opensearch-2-analysis-smartcnpkg:apk/wolfi/opensearch-2-analysis-stempelpkg:apk/wolfi/opensearch-2-analysis-ukrainianpkg:apk/wolfi/opensearch-2-anomaly-detectionpkg:apk/wolfi/opensearch-2-asynchronous-searchpkg:apk/wolfi/opensearch-2-cross-cluster-replicationpkg:apk/wolfi/opensearch-2-crypto-kmspkg:apk/wolfi/opensearch-2-custom-codecspkg:apk/wolfi/opensearch-2-discovery-azure-classicpkg:apk/wolfi/opensearch-2-discovery-ec2pkg:apk/wolfi/opensearch-2-discovery-gcepkg:apk/wolfi/opensearch-2-geospatialpkg:apk/wolfi/opensearch-2-identity-shiropkg:apk/wolfi/opensearch-2-index-managementpkg:apk/wolfi/opensearch-2-ingest-attachmentpkg:apk/wolfi/opensearch-2-job-schedulerpkg:apk/wolfi/opensearch-2-k-nnpkg:apk/wolfi/opensearch-2-mapper-annotated-textpkg:apk/wolfi/opensearch-2-mapper-murmur3pkg:apk/wolfi/opensearch-2-mapper-sizepkg:apk/wolfi/opensearch-2-ml-commonspkg:apk/wolfi/opensearch-2-neural-searchpkg:apk/wolfi/opensearch-2-notificationspkg:apk/wolfi/opensearch-2-observabilitypkg:apk/wolfi/opensearch-2-performance-analyzerpkg:apk/wolfi/opensearch-2-reportingpkg:apk/wolfi/opensearch-2-repository-azurepkg:apk/wolfi/opensearch-2-repository-gcspkg:apk/wolfi/opensearch-2-repository-s3pkg:apk/wolfi/opensearch-2-securitypkg:apk/wolfi/opensearch-2-security-analyticspkg:apk/wolfi/opensearch-2-sqlpkg:apk/wolfi/opensearch-2-store-smbpkg:apk/wolfi/opensearch-2-telemetry-otelpkg:apk/wolfi/opensearch-2-transport-niopkg:maven/ai.djl/api
< 2.15.0-r0+ 124 more
- (no CPE)range: < 2.15.0-r0
- (no CPE)range: < 2.15.0-r0
- (no CPE)range: < 2.15.0-r0
- (no CPE)range: < 2.15.0-r0
- (no CPE)range: < 2.15.0-r0
- (no CPE)range: < 2.15.0-r0
- (no CPE)range: < 2.15.0-r0
- (no CPE)range: < 2.15.0-r0
- (no CPE)range: < 2.15.0-r0
- (no CPE)range: < 2.15.0-r0
- (no CPE)range: < 2.15.0-r0
- (no CPE)range: < 2.15.0-r0
- (no CPE)range: < 2.15.0-r0
- (no CPE)range: < 2.15.0-r0
- (no CPE)range: < 2.15.0-r0
- (no CPE)range: < 2.15.0-r0
- (no CPE)range: < 2.15.0-r0
- (no CPE)range: < 2.15.0-r0
- (no CPE)range: < 2.15.0-r0
- (no CPE)range: < 2.15.0-r0
- (no CPE)range: < 2.15.0-r0
- (no CPE)range: < 2.15.0-r0
- (no CPE)range: < 2.15.0-r0
- (no CPE)range: < 2.14.0-r0
- (no CPE)range: < 2.14.0-r0
- (no CPE)range: < 2.14.0-r0
- (no CPE)range: < 2.14.0-r0
- (no CPE)range: < 2.14.0-r0
- (no CPE)range: < 2.14.0-r0
- (no CPE)range: < 2.14.0-r0
- (no CPE)range: < 2.14.0-r0
- (no CPE)range: < 2.14.0-r0
- (no CPE)range: < 2.14.0-r0
- (no CPE)range: < 2.14.0-r0
- (no CPE)range: < 2.14.0-r0
- (no CPE)range: < 2.14.0-r0
- (no CPE)range: < 2.14.0-r0
- (no CPE)range: < 2.14.0-r0
- (no CPE)range: < 2.14.0-r0
- (no CPE)range: < 2.14.0-r0
- (no CPE)range: < 2.14.0-r0
- (no CPE)range: < 2.14.0-r0
- (no CPE)range: < 2.14.0-r0
- (no CPE)range: < 2.14.0-r0
- (no CPE)range: < 2.14.0-r0
- (no CPE)range: < 2.14.0-r0
- (no CPE)range: < 2.14.0-r0
- (no CPE)range: < 2.14.0-r0
- (no CPE)range: < 2.14.0-r0
- (no CPE)range: < 2.14.0-r0
- (no CPE)range: < 2.14.0-r0
- (no CPE)range: < 2.14.0-r0
- (no CPE)range: < 2.14.0-r0
- (no CPE)range: < 2.14.0-r0
- (no CPE)range: < 2.14.0-r0
- (no CPE)range: < 2.14.0-r0
- (no CPE)range: < 2.14.0-r0
- (no CPE)range: < 2.14.0-r0
- (no CPE)range: < 2.14.0-r0
- (no CPE)range: < 2.14.0-r0
- (no CPE)range: < 2.14.0-r0
- (no CPE)range: < 2.14.0-r0
- (no CPE)range: < 2.14.0-r0
- (no CPE)range: < 2.14.0-r0
- (no CPE)range: < 2.15.0-r0
- (no CPE)range: < 2.15.0-r0
- (no CPE)range: < 2.15.0-r0
- (no CPE)range: < 2.15.0-r0
- (no CPE)range: < 2.15.0-r0
- (no CPE)range: < 2.15.0-r0
- (no CPE)range: < 2.15.0-r0
- (no CPE)range: < 2.15.0-r0
- (no CPE)range: < 2.15.0-r0
- (no CPE)range: < 2.15.0-r0
- (no CPE)range: < 2.15.0-r0
- (no CPE)range: < 2.15.0-r0
- (no CPE)range: < 2.15.0-r0
- (no CPE)range: < 2.15.0-r0
- (no CPE)range: < 2.15.0-r0
- (no CPE)range: < 2.15.0-r0
- (no CPE)range: < 2.15.0-r0
- (no CPE)range: < 2.15.0-r0
- (no CPE)range: < 2.15.0-r0
- (no CPE)range: < 2.15.0-r0
- (no CPE)range: < 2.15.0-r0
- (no CPE)range: < 2.15.0-r0
- (no CPE)range: < 2.15.0-r0
- (no CPE)range: < 2.15.0-r0
- (no CPE)range: < 2.15.0-r0
- (no CPE)range: < 2.15.0-r0
- (no CPE)range: < 2.15.0-r0
- (no CPE)range: < 2.15.0-r0
- (no CPE)range: < 2.15.0-r0
- (no CPE)range: < 2.15.0-r0
- (no CPE)range: < 2.15.0-r0
- (no CPE)range: < 2.15.0-r0
- (no CPE)range: < 2.15.0-r0
- (no CPE)range: < 2.15.0-r0
- (no CPE)range: < 2.15.0-r0
- (no CPE)range: < 2.15.0-r0
- (no CPE)range: < 2.15.0-r0
- (no CPE)range: < 2.15.0-r0
- (no CPE)range: < 2.15.0-r0
- (no CPE)range: < 2.15.0-r0
- (no CPE)range: < 2.15.0-r0
- (no CPE)range: < 2.15.0-r0
- (no CPE)range: < 2.15.0-r0
- (no CPE)range: < 2.15.0-r0
- (no CPE)range: < 2.15.0-r0
- (no CPE)range: < 2.15.0-r0
- (no CPE)range: < 2.15.0-r0
- (no CPE)range: < 2.15.0-r0
- (no CPE)range: < 2.15.0-r0
- (no CPE)range: < 2.15.0-r0
- (no CPE)range: < 2.15.0-r0
- (no CPE)range: < 2.15.0-r0
- (no CPE)range: < 2.15.0-r0
- (no CPE)range: < 2.15.0-r0
- (no CPE)range: < 2.15.0-r0
- (no CPE)range: < 2.15.0-r0
- (no CPE)range: < 2.15.0-r0
- (no CPE)range: < 2.15.0-r0
- (no CPE)range: < 2.15.0-r0
- (no CPE)range: < 2.15.0-r0
- (no CPE)range: >= 0.1.0, < 0.28.0
Patches
Vulnerability mechanics
References
8- github.com/advisories/GHSA-w877-jfw7-46rjghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-37902ghsaADVISORY
- github.com/aws/deep-learning-containers/releases/tag/v1.1-djl-0.27.0-inf-cpu-fullghsaWEB
- github.com/aws/deep-learning-containers/releases/tag/v1.3-djl-0.27.0-inf-neuronx-sdk2.18.1ghsaWEB
- github.com/aws/deep-learning-containers/releases/tag/v1.4-djl-0.27.0-inf-ds-0.12.6ghsaWEB
- github.com/aws/deep-learning-containers/releases/tag/v1.4-djl-0.27.0-inf-trt-0.8.0ghsaWEB
- github.com/deepjavalibrary/djl/releases/tag/v0.28.0nvdWEB
- github.com/deepjavalibrary/djl/security/advisories/GHSA-w877-jfw7-46rjnvdWEB
News mentions
0No linked articles in our index yet.