CVE-2024-3660: Arbitrary code injection vulnerability in Keras framework < 2.13
Published Apr 16, 2024
·Updated
A arbitrary code injection vulnerability in TensorFlow's Keras framework (<2.13) allows attackers to execute arbitrary code with the same permissions as the application using a model that allow arbitrary code irrespective of the application.
Affected Software
2 affected componentsFixes available
pip/keras<2.13.1rc0
2.13.1rc0
Keras Keras<2.13.1
Event History
Apr 16, 2024
CVE Published
via MITRE·08:09 PM
Data Sourced
via MITRE·08:09 PM
DescriptionWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverity
Data Sourced
via NVD·09:15 PM
WeaknessAffected Software
Advisory Published
via GitHub·09:31 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-3660?
CVE-2024-3660 is considered a critical vulnerability due to the potential for arbitrary code execution.
2
How can I fix CVE-2024-3660?
To fix CVE-2024-3660, upgrade TensorFlow's Keras framework to version 2.13.1rc0 or later.
3
Who is affected by CVE-2024-3660?
CVE-2024-3660 affects users of TensorFlow's Keras framework versions before 2.13.1rc0.
4
What type of vulnerability is CVE-2024-3660?
CVE-2024-3660 is an arbitrary code injection vulnerability.
5
What could an attacker do with CVE-2024-3660?
An attacker could execute arbitrary code with the same permissions as the application using the vulnerable Keras model.