Beveiligingsadvies

CVE-2024-3660

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2024-04-16 20:09:26
Laatst bijgewerkt 2025-02-13 17:52:58
Toegewezen door certcc
CVSS-score 9.8
Status PUBLISHED

Beschrijving

A arbitrary code injection vulnerability in TensorFlow's Keras framework (<2.13) allows attackers to execute arbitrary code with the same permissions as the application using a model that allow arbitrary code irrespective of the application.