4.6
CVSSv2

CVE-2021-37678

Published: 12/08/2021 Updated: 19/08/2021
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
CVSS v3 Base Score: 8.8 | Impact Score: 6 | Exploitability Score: 2
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

TensorFlow is an end-to-end open source platform for machine learning. In affected versions TensorFlow and Keras can be tricked to perform arbitrary code execution when deserializing a Keras model from YAML format. The [implementation](github.com/tensorflow/tensorflow/blob/460e000de3a83278fb00b61a16d161b1964f15f4/tensorflow/python/keras/saving/model_config.py#L66-L104) uses `yaml.unsafe_load` which can perform arbitrary code execution on the input. Given that YAML format support requires a significant amount of work, we have removed it for now. We have patched the issue in GitHub commit 23d6383eb6c14084a8fc3bdf164043b974818012. The fix will be included in TensorFlow 2.6.0. We will also cherrypick this commit on TensorFlow 2.5.1, TensorFlow 2.4.3, and TensorFlow 2.3.4, as these are also affected and still in supported range.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

google tensorflow

google tensorflow 2.5.0

google tensorflow 2.6.0

Vendor Advisories

In TensorFlow before version 260 TensorFlow and Keras can be tricked to perform arbitrary code execution when deserializing a Keras model from YAML format The implementation uses yamlunsafe_load which can perform arbitrary code execution on the input Given that YAML format support requires a significant amount of work, it has been removed it f ...

Github Repositories

TP Seguridad Informática UTN FRBA 2021

CVE-2021-37678 Exploit Para explotar la vulnerabilidad, es necesario levantar un contenedor docker con un ambiente preparado para levantar Tensorflow con una versión 223 la cual todavía tiene la vulnerabilidad Consta de: Una arquitectura AMD de 64 bits, CPU o GPU que puede ejecutar instrucciones AVX Python de 64 bits en la versión 369 Pip3 en la versi