CVE-2022-23590
MEDIUMGoogle Tensorflow < 2.7.1 - Improper Condition Check
Title source: ruleDescription
Tensorflow is an Open Source Machine Learning Framework. A `GraphDef` from a TensorFlow `SavedModel` can be maliciously altered to cause a TensorFlow process to crash due to encountering a `StatusOr` value that is an error and forcibly extracting the value from it. We have patched the issue in multiple GitHub commits and these will be included in TensorFlow 2.8.0 and TensorFlow 2.7.1, as both are affected.
References (3)
Core 3
Core References
Patch, Third Party Advisory x_refsource_confirm
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-pqrv-8r2f-7278
Patch, Third Party Advisory x_refsource_misc
https://github.com/tensorflow/tensorflow/commit/955059813cc325dc1db5e2daa6221271406d4439
Exploit, Third Party Advisory x_refsource_misc
https://github.com/tensorflow/tensorflow/blob/274df9b02330b790aa8de1cee164b70f72b9b244/tensorflow/core/graph/graph.cc#L560-L567
Scores
CVSS v3
5.9
EPSS
0.0024
EPSS Percentile
46.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-754
Status
published
Products (4)
google/tensorflow
< 2.7.1
pypi/tensorflow
0 - 2.7.1PyPI
pypi/tensorflow-cpu
0 - 2.7.1PyPI
pypi/tensorflow-gpu
0 - 2.7.1PyPI
Published
Feb 04, 2022
Tracked Since
Feb 18, 2026