VDB
CVE-2021-35958
CVE-2021-35958
PUBLISHED
CVSS 9.100000381469727 CRITICAL
TensorFlow through 2.5.0 allows attackers to overwrite arbitrary files via a crafted archive when tf.keras.utils.get_file is used with extract=True. NOTE: the vendor's position is that tf.keras.utils.get_file is not intended for untrusted archives
EPSS 1.86% · 78.2th percentile
Risk Scores
CVSS 3.1
9.100000381469727
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
EPSS Score
1.86%
78.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bitnami | tensorflow | 0 |
| Bitnami | tensorflow | 0 |
Timeline
- Jun 30, 2021 CVE Published
- Jun 30, 2021 EPSS Score
- Jul 6, 2021 CVE Updated
- Aug 18, 2021 EPSS Score
- Oct 29, 2021 EPSS Score
- Dec 28, 2021 EPSS Score
- Feb 4, 2022 EPSS Score
- Feb 27, 2022 EPSS Score
- Apr 28, 2022 EPSS Score
- Jun 28, 2022 EPSS Score
- Oct 28, 2022 EPSS Score
- Dec 27, 2022 EPSS Score
References
- https://docs.python.org/3/library/tarfile.html#tarfile.TarFile.extractall url
- https://github.com/tensorflow/tensorflow/blob/b8cad4c631096a34461ff8a07840d5f4d123ce32/tensorflow/python/keras/utils/data_utils.py#L137 url
- https://github.com/tensorflow/tensorflow/blob/b8cad4c631096a34461ff8a07840d5f4d123ce32/tensorflow/python/keras/README.md url
- https://keras.io/api/ url
- https://vuln.ryotak.me/advisories/52 url
- https://nvd.nist.gov/vuln/detail/CVE-2021-35958 url