CVE-2025-0508
MEDIUM5.9EPSS 0.14%SageMaker Workflow component allows possibility of MD5 hash collisions
發布日:2025/3/20修改日:2025/10/16
描述
A vulnerability in the SageMaker Workflow component of aws/sagemaker-python-sdk allows for the possibility of MD5 hash collisions in all versions. This can lead to workflows being inadvertently replaced due to the reuse of results from different configurations that produce the same MD5 hash. This issue can cause integrity problems within the pipeline, potentially leading to erroneous processing outcomes.
受影響套件(1)
- PyPI/sagemakerfrom 0, < 2.237.3
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.9 | CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N |