CVE-2021-35958 log

Source
Severity Medium
Remote Yes
Type Arbitrary file overwrite
Description
** DISPUTED ** TensorFlow through 2.5.0 allows attackers to overwrite arbitrary files via a crafted archive when tf.keras.utils.get_file is used with extract=True. NOTE: the vendor's position is that tf.keras.utils.get_file is not intended for untrusted archives.
Group Package Affected Fixed Severity Status Ticket
AVG-2114 tensorflow 2.7.0-4 Medium Vulnerable
References
https://vuln.ryotak.me/advisories/52
https://docs.python.org/3/library/tarfile.html#tarfile.TarFile.extractall