Safety vulnerability ID: 43744
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Torchserve 0.5.1 updates its dependency 'log4j2' to v2.16.0 to fix critical vulnerabilities.
Latest version: 0.12.0
TorchServe is a tool for serving neural net models for inference
This is a hotfix release of Log4j issue.
Log4j Fixing
+ **Upgrade [log4j2](https://logging.apache.org/log4j/2.x/security.html) version to 2.16.0** - Added [log4j upgrade](https://github.com/pytorch/serve/pull/1364) to address [CVE-2021-44228](https://www.lunasec.io/docs/blog/log4j-zero-day/) and [CVE-2021-45046](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-45046).
New Features
+ **IPEX launcher support** - Added [support](https://github.com/pytorch/serve/pull/1354) for [Intel extension for PyTorch](https://intel.github.io/intel-extension-for-pytorch/).
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application