PyPI package
horovod
pkg:pypi/horovod
Vulnerabilities (2)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2024-10190 | — | <= 0.28.1 | — | Mar 20, 2025 | Horovod versions up to and including v0.28.1 are vulnerable to unauthenticated remote code execution. The vulnerability is due to improper handling of base64-encoded data in the `ElasticRendezvousHandler`, a subclass of `KVStoreHandler`. Specifically, the `_put_value` method in ` | ||
| CVE-2022-0315 | — | < 0.24.0 | 0.24.0 | Mar 24, 2022 | Insecure Temporary File in GitHub repository horovod/horovod prior to 0.24.0. |
- CVE-2024-10190Mar 20, 2025affected <= 0.28.1
Horovod versions up to and including v0.28.1 are vulnerable to unauthenticated remote code execution. The vulnerability is due to improper handling of base64-encoded data in the `ElasticRendezvousHandler`, a subclass of `KVStoreHandler`. Specifically, the `_put_value` method in `
- CVE-2022-0315Mar 24, 2022affected < 0.24.0fixed 0.24.0
Insecure Temporary File in GitHub repository horovod/horovod prior to 0.24.0.