Advisory Database
  • Advisories
  • Dependency Scanning
  1. pypi
  2. ›
  3. tensorflow-gpu
  4. ›
  5. CVE-2022-23563

CVE-2022-23563: Insecure temporary file in Tensorflow

February 9, 2022 (updated November 13, 2024)

In multiple places, TensorFlow uses tempfile.mktemp to create temporary files. While this is acceptable in testing, in utilities and libraries it is dangerous as a different process can create the file between the check for the filename in mktemp and the actual creation of the file by a subsequent operation (a TOC/TOU type of weakness).

In several instances, TensorFlow was supposed to actually create a temporary directory instead of a file. This logic bug is hidden away by the mktemp function usage.

References

  • github.com/advisories/GHSA-wc4g-r73w-x8mm
  • github.com/pypa/advisory-database/tree/main/vulns/tensorflow-cpu/PYSEC-2022-72.yaml
  • github.com/pypa/advisory-database/tree/main/vulns/tensorflow-gpu/PYSEC-2022-127.yaml
  • github.com/tensorflow/tensorflow
  • github.com/tensorflow/tensorflow/security/advisories/GHSA-wc4g-r73w-x8mm
  • nvd.nist.gov/vuln/detail/CVE-2022-23563

Code Behaviors & Features

Detect and mitigate CVE-2022-23563 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 2.5.3, all versions starting from 2.6.0 before 2.6.3, all versions starting from 2.7.0 before 2.7.1, version 2.7.0

Fixed versions

  • 2.5.3
  • 2.6.3
  • 2.7.1

Solution

Upgrade to versions 2.5.3, 2.6.3, 2.7.1 or above.

Impact 6.3 MEDIUM

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N

Learn more about CVSS

Weakness

  • CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition
  • CWE-668: Exposure of Resource to Wrong Sphere

Source file

pypi/tensorflow-gpu/CVE-2022-23563.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:14:48 +0000.