Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Andey Robins

Researcher fromCybersecurity Education and Research Lab in the Department of Computer Science at the University of Wyoming
#32462of 53,632
7.8Total CVSS
Vulnerabilities · 1
PT-2022-19469
7.8
2022-05-20
Google · Tensorflow · CVE-2022-29216
**Name of the Vulnerable Software and Affected Versions** TensorFlow versions prior to 2.9.0 TensorFlow versions prior to 2.8.1 TensorFlow versions prior to 2.7.2 TensorFlow versions prior to 2.6.4 **Description** TensorFlow is an open source platform for machine learning. The `saved model cli` tool is vulnerable to a code injection, which can be used to open a reverse shell. This code path was maintained for compatibility reasons as the maintainers had several test cases where numpy expressions were used as arguments. However, given that the tool is always run manually, the impact of this is still not severe. The maintainers have now removed the `safe=False` argument, so all parsing is done without calling `eval`. **Recommendations** For versions prior to 2.9.0, update to version 2.9.0 or later. For versions prior to 2.8.1, update to version 2.8.1 or later. For versions prior to 2.7.2, update to version 2.7.2 or later. For versions prior to 2.6.4, update to version 2.6.4 or later.