Code Injection in GitHub repository pytorchlightning/pytorch-lightning prior to 1.6.0.
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
Link | Tags |
---|---|
https://huntr.dev/bounties/a795bf93-c91e-4c79-aae8-f7d8bda92e2a | patch exploit third party advisory issue tracking |
https://github.com/pytorchlightning/pytorch-lightning/commit/8b7a12c52e52a06408e9231647839ddb4665e8ae | third party advisory patch |