Skip to content

Vulnerabilities CVE-2024-43598 & sonatype-2024-013191 found in the latest v4.5.0 #6759

@OlgasAcc

Description

@OlgasAcc

Description

Hello,
Our Sonatype security scanner has detected CVE sonatype-2024-013191 and https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43598 in the latest version of the lightgbm– v4.5.0 (and in the current version we use for our python services - v4.0.0).

Image Image

Based on the Sonatype description, there is no non-vulnerable version available.
Could you please provide the necessary fix and release?

Thanks

Image

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions