CVE-2023-2800: Insecure Temporary File in huggingface/transformers
Insecure Temporary File in GitHub repository huggingface/transformers 4.29.2 and prior. A fix is available at commit 80ca92470938bbcc348e2d9cf4734c7c25cb1c43 and has been released as part of version 4.30.0.
Other sources
Insecure Temporary File in GitHub repository huggingface/transformers prior to 4.30.0.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2023-2800.
What is the title of the vulnerability?
The title of the vulnerability is 'Insecure Temporary File in GitHub repository huggingface/transformers prior to 4.30.0.'
What is the severity of CVE-2023-2800?
The severity of CVE-2023-2800 is medium with a severity value of 4.7.
How can I fix the vulnerability?
You can fix the vulnerability by updating to version 4.30.0 of the huggingface/transformers GitHub repository or using pip to install version 4.30.0 of the 'transformers' package.
Where can I find more information about CVE-2023-2800?
You can find more information about CVE-2023-2800 at the following references: [GitHub commit](https://github.com/huggingface/transformers/commit/80ca92470938bbcc348e2d9cf4734c7c25cb1c43), [Huntr Security Advisory](https://huntr.dev/bounties/a3867b4e-6701-4418-8c20-3c6e7084a44a), [NVD NIST Vulnerability Detail](https://nvd.nist.gov/vuln/detail/CVE-2023-2800).