CVE-2021-35958 log
| Source |
|
| Severity | Medium |
| Remote | Yes |
| Type | Arbitrary file overwrite |
| Description | ** DISPUTED ** TensorFlow through 2.5.0 allows attackers to overwrite arbitrary files via a crafted archive when tf.keras.utils.get_file is used with extract=True. NOTE: the vendor's position is that tf.keras.utils.get_file is not intended for untrusted archives. |
| Group | Package | Affected | Fixed | Severity | Status | Ticket |
|---|---|---|---|---|---|---|
| AVG-2114 | tensorflow | 2.7.0-4 | Medium | Vulnerable |
| References |
|---|
https://vuln.ryotak.me/advisories/52 https://docs.python.org/3/library/tarfile.html#tarfile.TarFile.extractall |