huawei-noah / vega

AutoML tools chain
http://www.noahlab.com.hk/opensource/vega/
Other
845 stars 176 forks source link

vega存在pickle.loads、pickle.load等相关调用 #164

Closed jiangzc86 closed 3 years ago

jiangzc86 commented 3 years ago

Pickle and modules that wrap it can be unsafe when used to deserialize untrusted data, possible security issue.

./contrib/vega/algorithms/nas/auto_lane_v2/lane_model_pytorch/dataloaders/datasets/readymade_lane.py ./contrib/vega/algorithms/nas/auto_lane_v2/lane_model_pytorch/dataloaders/datasets/readymade_lane.py ./contrib/vega/algorithms/nas/sm_nas/tools/test.py ./vega/algorithms/auto_loss/adaptive_muti_loss.py ./vega/algorithms/nas/modnas/estim/base.py ./vega/algorithms/nas/modnas/metrics/predefined/stats.py ./vega/common/file_ops.py ./vega/core/pipeline/generator.py ./vega/core/pipeline/horovod/horovod_train.py ./vega/datasets/common/cifar10.py ./vega/datasets/common/cifar100.py ./vega/datasets/common/cityscapes.py ./vega/datasets/common/cityscapes.py ./vega/datasets/common/utils/div2k_util.py ./vega/evaluator/tools/pytorch2caffe.py ./vega/evaluator/tools/pytorch2caffe.py ./vega/op_search/main.py ./vega/op_search/main.py ./vega/report/report_server.py ./vega/trainer/deserialize.py ./vega/trainer/deserialize.py ./vega/trainer/trial_agent.py

image

image

image