Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cjgq-5qmw-rcj6

Опубликовано: 08 янв. 2025
Источник: github
Github: Прошло ревью
CVSS4: 5.5

Описание

keras Path Traversal vulnerability

An issue in keras 3.7.0 allows attackers to write arbitrary files to the user's machine via downloading a crafted tar file through the get_file function.

Пакеты

Наименование

keras

pip
Затронутые версииВерсия исправления

<= 3.7.0

Отсутствует

EPSS

Процентиль: 22%
0.00071
Низкий

5.5 Medium

CVSS4

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 6.5
ubuntu
11 месяцев назад

An issue in keras 3.7.0 allows attackers to write arbitrary files to the user's machine via downloading a crafted tar file through the get_file function.

CVSS3: 5.7
redhat
11 месяцев назад

An issue in keras 3.7.0 allows attackers to write arbitrary files to the user's machine via downloading a crafted tar file through the get_file function.

CVSS3: 6.5
nvd
11 месяцев назад

An issue in keras 3.7.0 allows attackers to write arbitrary files to the user's machine via downloading a crafted tar file through the get_file function.

msrc
3 месяца назад

An issue in keras 3.7.0 allows attackers to write arbitrary files to the user's machine via downloading a crafted tar file through the get_file function.

CVSS3: 6.5
debian
11 месяцев назад

An issue in keras 3.7.0 allows attackers to write arbitrary files to t ...

EPSS

Процентиль: 22%
0.00071
Низкий

5.5 Medium

CVSS4

Дефекты

CWE-22