We observed a vulnerability in commons-text-1.6.jar and is vulnerable to CVE-2022-42889 which exists in versions >= 1.5, < 1.10.0.
To mitigate this vulnerability, we upgraded the package version to 0.9.17 from 0.9.12. The model has started giving “None” in the responses when we call predict method with our request data. Responses are as expected with the old version.
Can some one please help?
enter image description here
I tried downgrading package back to 0.9.12 and its working as expected, when I downgraded to first ever version of this package 0.9.0, then also, it is working. I cannot use lower versions of this package since its having common text jar file vulnerability.
Tharun Kumar Baliwada is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
Check out our Code of Conduct.