CVE Published: 16/04/2024 |
CVE Updated: 01/08/2024 |
CVE Year: 2024 Source: certcc |
Vendor: tensorflow |
Product: keras Status : PUBLISHED
CVE-2024-3660 Description
A arbitrary code injection vulnerability in TensorFlow\'s Keras framework (<2.13) allows attackers to execute arbitrary code with the same permissions as the application using a model that allow arbitrary code irrespective of the application.