Security Advisory

CVE-2024-3660

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2024-04-16 20:09:26
Last updated 2025-02-13 17:52:58
Assigner certcc
State PUBLISHED

Description

A arbitrary code injection vulnerability in TensorFlows Keras framework (<2.13) allows attackers to execute arbitrary code with the same permissions as the application using a model that allow arbitrary code irrespective of the application.