Deep Dive: CVE-2024-37902 and Potential Impact on DeepJavaLibrary Users

A warning sign labeled DJL DeepJavaLibrary CVE-2024-37902 stands on a sandy beach with palm trees. In the background, a large wave crashes, and a surfboard is visible in the surf.

AWS announced today, June 17, that there is a potential security issue with archive extraction utilities in DeepJavaLibrary versions 0.1.0 through 0.27.0 that could allow an attacker to tamper with your system. What is DeepJavaLibrary? DJL is a free, open-source library by AWS used for building deep learning models in Java. It provides easy-to-use tools […]