Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4cm9-63x5-55wm

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.1

Описание

** DISPUTED ** TensorFlow through 2.5.0 allows attackers to overwrite arbitrary files via a crafted archive when tf.keras.utils.get_file is used with extract=True. NOTE: the vendor's position is that tf.keras.utils.get_file is not intended for untrusted archives.

** DISPUTED ** TensorFlow through 2.5.0 allows attackers to overwrite arbitrary files via a crafted archive when tf.keras.utils.get_file is used with extract=True. NOTE: the vendor's position is that tf.keras.utils.get_file is not intended for untrusted archives.

EPSS

Процентиль: 78%
0.01093
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-22
CWE-668

Связанные уязвимости

CVSS3: 9.1
nvd
больше 4 лет назад

TensorFlow through 2.5.0 allows attackers to overwrite arbitrary files via a crafted archive when tf.keras.utils.get_file is used with extract=True. NOTE: the vendor's position is that tf.keras.utils.get_file is not intended for untrusted archives

CVSS3: 9.1
debian
больше 4 лет назад

TensorFlow through 2.5.0 allows attackers to overwrite arbitrary files ...

EPSS

Процентиль: 78%
0.01093
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-22
CWE-668