BIT-tensorflow-2022-29216

    Dashboard / Vulnerabilities / BIT-tensorflow-2022-29216

    BIT-tensorflow-2022-29216

    Published: 6 Mar 2024Last Modified: 8 Sept 2026

    Summary: Code injection in `saved_model_cli` in TensorFlow

    Details: TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, TensorFlow's `saved_model_cli` tool is vulnerable to a code injection. This can be used to open a reverse shell. This code path was maintained for compatibility reasons as the maintainers had several test cases where numpy expressions were used as arguments. However, given that the tool is always run manually, the impact of this is still not severe. The maintainers have now removed the `safe=False` argument, so all parsing is done without calling `eval`. The patch is available in versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4.

    Affected packages

    Package

    Name: tensorflow

    Purl: pkg:bitnami/tensorflow

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -2.6.4

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    BIT-tensorflow-2022-29216 | CVE-DB