CVE-2024-3660: Arbitrary code injection vulnerability in Keras framework < 2.13
A arbitrary code injection vulnerability in TensorFlow's Keras framework (<2.13) allows attackers to execute arbitrary code with the same permissions as the application using a model that allow arbitrary code irrespective of the application.
Other sources
Arbitrary code injection vulnerability in Keras framework < 2.13
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/kerasto a version that resolves this vulnerability.Fixed in 2.13.1rc0
Event History
Frequently Asked Questions
What is the severity of CVE-2024-3660?
CVE-2024-3660 is considered a critical vulnerability due to the potential for arbitrary code execution.
How can I fix CVE-2024-3660?
To fix CVE-2024-3660, upgrade TensorFlow's Keras framework to version 2.13.1rc0 or later.
Who is affected by CVE-2024-3660?
CVE-2024-3660 affects users of TensorFlow's Keras framework versions before 2.13.1rc0.
What type of vulnerability is CVE-2024-3660?
CVE-2024-3660 is an arbitrary code injection vulnerability.
What could an attacker do with CVE-2024-3660?
An attacker could execute arbitrary code with the same permissions as the application using the vulnerable Keras model.