wandb is vulnerable to Use of a Broken or Risky Cryptographic Algorithm
23
Low Risk
ArtifactManifestEntry.download in wandb/sdk/lib/hashutil.py verifies downloaded artifact content against a manifest digest computed with a weak hash algorithm. A collision against that weak hash lets a downloaded file differ from what the manifest claims without the integrity check catching it. Exploiting this requires the ability to influence the artifact manifest or storage backend and is difficult to carry out reliably. The fix addresses the check by moving to a stronger hash.
You are affected if you are using a version that falls within the vulnerable range.
wandb is vulnerable to Use of a Broken or Risky Cryptographic Algorithm in versions 0.0.1 - 0.28.2.
Upgrade the wandb library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.