CVE-2023-5245
CVSS 3.1 Score 7.8 of 10 (high)
Details
Published Nov 15, 2023
Updated: Nov 22, 2023
CWE ID 129
Summary
CVE-2023-5245 is a vulnerability affecting TensorFlow's FileUtil.extract() function. This issue allows arbitrary file creation during the process of extracting files from zip archives when using TensorFlowModel with the saved_model format. The function fails to validate file paths, enabling an attacker to extract files outside of the intended directory. This vulnerability can result in code execution, posing a significant security risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share