Количество 3
Количество 3
CVE-2021-35958
TensorFlow through 2.5.0 allows attackers to overwrite arbitrary files via a crafted archive when tf.keras.utils.get_file is used with extract=True. NOTE: the vendor's position is that tf.keras.utils.get_file is not intended for untrusted archives
CVE-2021-35958
TensorFlow through 2.5.0 allows attackers to overwrite arbitrary files ...
GHSA-4cm9-63x5-55wm
** DISPUTED ** TensorFlow through 2.5.0 allows attackers to overwrite arbitrary files via a crafted archive when tf.keras.utils.get_file is used with extract=True. NOTE: the vendor's position is that tf.keras.utils.get_file is not intended for untrusted archives.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2021-35958 TensorFlow through 2.5.0 allows attackers to overwrite arbitrary files via a crafted archive when tf.keras.utils.get_file is used with extract=True. NOTE: the vendor's position is that tf.keras.utils.get_file is not intended for untrusted archives | CVSS3: 9.1 | 1% Низкий | больше 4 лет назад | |
CVE-2021-35958 TensorFlow through 2.5.0 allows attackers to overwrite arbitrary files ... | CVSS3: 9.1 | 1% Низкий | больше 4 лет назад | |
GHSA-4cm9-63x5-55wm ** DISPUTED ** TensorFlow through 2.5.0 allows attackers to overwrite arbitrary files via a crafted archive when tf.keras.utils.get_file is used with extract=True. NOTE: the vendor's position is that tf.keras.utils.get_file is not intended for untrusted archives. | CVSS3: 9.1 | 1% Низкий | больше 3 лет назад |
Уязвимостей на страницу