セキュリティ

SGLang に Pickle のデシリアライゼーションに関する脆弱性

セキュリティ 元記事

予習

この記事のキーワード — タップで意味
×1
本件
ほんけん
this matter; this case
×2
関する
かんする
to concern; to be related
×1
参照
さんしょう
reference; bibliographical reference; consultation; browsing (e.g. when selecting a file to upload on a computer); checking out
N1
×1
一般社団法人
いっぱんしゃだんほうじん
general incorporated association
×1
独立行政法人
どくりつぎょうせいほうじん
independent administrative corporation (institution, agency)
 独立行政法人情報処理推進機構(IPA)および一般社団法人JPCERT コーディネーションセンター(JPCERT/CC)は7月17日、SGLangにおけるPickleのデシリアライゼーションに関する脆弱性について「Japan Vulnerability Notes(JVN)」で発表した。CERT/CCが本件関するアドバイザリを公表している。

 JVNでは、影響を受けるシステム、想定される影響対策方法についてはCERT/CCのアドバイザリを参照するよう案内している。

Vulnerability Note VU#326070 SGLang contains a vulnerable pickle deserialization vulnerability through the expert-parallel subsystem

この記事の単語 (14)

×2
関する
かんする
to concern; to be related
×2
影響
えいきょう
1. influence; effect 2. to influence; to affect; to have an influence on; to impact; to have an effect on
×1
独立行政法人
どくりつぎょうせいほうじん
independent administrative corporation (institution, agency)
×1
情報処理推進機構
じょうほうしょりすいしんきこう
Information-technology Promotion Agency (organization)
×1
及び
および
and; as well as
×1
一般社団法人
いっぱんしゃだんほうじん
general incorporated association
×1
脆弱性
ぜいじゃくせい
vulnerability; weakness; fragility
×1
発表
はっぴょう
announcement; publication; presenting; statement; communique; making known; breaking (news story); expressing (one's opinion); releasing; unveiling
×1
本件
ほんけん
this matter; this case
×1
公表
こうひょう
official announcement; proclamation
×1
想定
そうてい
hypothesis; supposition; assumption
×1
対策
たいさく
measure; step; countermeasure; counterplan; countermove; strategy; preparation (e.g. for a test)
×1
方法
ほうほう
method; process; manner; way; means; technique
×1
参照
さんしょう
reference; bibliographical reference; consultation; browsing (e.g. when selecting a file to upload on a computer); checking out