CriticalVulnerability
GHSA-w7qg-j435-78qw: Use of hard-coded, security-relevant constants in deepset-ai/haystack
- Identifiers
- CVE-2023-1712GHSA-w7qg-j435-78qw
- Published
- Record updated
- Affected
- farm-haystack <= 1.15.0
- Fixed in
- No fixed version was stated when the source was last read.
- Known exploitation
- Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
- EPSS
- 0.9%
Summary
Haystack, the deepset-ai GitHub repository, uses hard-coded, security-relevant constants in version 1.15.0 and earlier. The advisory GHSA-w7qg-j435-78qw covers this use of fixed values where a secret or setting should not be fixed.
Mitigation
A patch is available at commit 5fc84904f198de661d5b933fde756aa922bf09f1.
Affected packages in the Exposure Registry
Matched by package name and ecosystem. Each entry shows whether the package delegates to a language model and how many tracked packages depend on it.
- farm-haystackPyPILLM dependency since 2019-11-28