First published: Thu May 18 2023(Updated: )
Insecure Temporary File in GitHub repository huggingface/transformers 4.29.2 and prior. A fix is available at commit 80ca92470938bbcc348e2d9cf4734c7c25cb1c43 and has been released as part of version 4.30.0.
Credit: security@huntr.dev security@huntr.dev
Affected Software | Affected Version | How to fix |
---|---|---|
Huggingface Transformers | <4.30.0 | |
pip/transformers | <4.30.0 | 4.30.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-2800.
The title of the vulnerability is 'Insecure Temporary File in GitHub repository huggingface/transformers prior to 4.30.0.'
The severity of CVE-2023-2800 is medium with a severity value of 4.7.
You can fix the vulnerability by updating to version 4.30.0 of the huggingface/transformers GitHub repository or using pip to install version 4.30.0 of the 'transformers' package.
You can find more information about CVE-2023-2800 at the following references: [GitHub commit](https://github.com/huggingface/transformers/commit/80ca92470938bbcc348e2d9cf4734c7c25cb1c43), [Huntr Security Advisory](https://huntr.dev/bounties/a3867b4e-6701-4418-8c20-3c6e7084a44a), [NVD NIST Vulnerability Detail](https://nvd.nist.gov/vuln/detail/CVE-2023-2800).