 
                        We found results for “”
CVE-2022-41888
Good to know:
 
                                    Date: November 17, 2022
TensorFlow is an open source platform for machine learning. When running on GPU, "tf.image.generate_bounding_box_proposals" receives a "scores" input that must be of rank 4 but is not checked. We have patched the issue in GitHub commit cf35502463a88ca7185a99daa7031df60b3c1c98. The fix will be included in TensorFlow 2.11. We will also cherrypick this commit on TensorFlow 2.10.1, 2.9.3, and TensorFlow 2.8.4, as these are also affected and still in supported range.
Language: Python
Severity Score
Related Resources (6)
Severity Score
Weakness Type (CWE)
Improper Input Validation
CWE-20Top Fix
 
                                    Upgrade Version
Upgrade to version tensorflow-cpu - 2.10.1;tensorflow-cpu - 2.9.3;tensorflow-cpu - 2.8.4;tensorflow - 2.10.1;tensorflow - 2.9.3;tensorflow - 2.8.4;tensorflow-gpu - 2.10.1;tensorflow-gpu - 2.8.4;tensorflow-gpu - 2.9.3
CVSS v3.1
| Base Score: |  | 
|---|---|
| Attack Vector (AV): | NETWORK | 
| Attack Complexity (AC): | HIGH | 
| Privileges Required (PR): | LOW | 
| User Interaction (UI): | REQUIRED | 
| Scope (S): | UNCHANGED | 
| Confidentiality (C): | NONE | 
| Integrity (I): | NONE | 
| Availability (A): | HIGH | 
 Vulnerabilities
                        Vulnerabilities
                 Projects
                        Projects
                 Vulnerability Disclosure
                        Vulnerability Disclosure
                 About Us
                    About Us
                 Contact Us
                    Contact Us
                

