Safety vulnerability ID: 43735
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Torchserve 0.5.2 updates its dependency 'log4j2' to v2.17.0 to fix a vulnerability.
Latest version: 0.12.0
TorchServe is a tool for serving neural net models for inference
This is a hotfix release of Log4j issue.
Log4j Fixing
+ **Upgrade [log4j2](https://logging.apache.org/log4j/2.x/security.html) version to 2.17.0** - Added [log4j upgrade](https://github.com/pytorch/serve/pull/1378) to address [CVE-2021-45105](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-45105).
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application