Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-41888


TensorFlow is an open source platform for machine learning. When running on GPU, `tf.image.generate_bounding_box_proposals` receives a `scores` input that must be of rank 4 but is not checked. We have patched the issue in GitHub commit cf35502463a88ca7185a99daa7031df60b3c1c98. The fix will be included in TensorFlow 2.11. We will also cherrypick this commit on TensorFlow 2.10.1, 2.9.3, and TensorFlow 2.8.4, as these are also affected and still in supported range.


Published

2022-11-18T22:15:15.203

Last Modified

2024-11-21T07:23:59.910

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 4.8 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-20

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application google tensorflow < 2.8.4 Yes
Application google tensorflow < 2.9.3 Yes
Application google tensorflow < 2.10.1 Yes

References