Improper Neutralization of Special Elements in Output Used by a Downstream Component in TensorFlow - CVE-2023-30767
Published: May 1, 2025
Vulnerability identifier: #VU108098
CSH Severity: Low
CVSS v4: 5.8 [CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-30767
CWE-ID: CWE-74
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to execute arbitrary code on the target system.
The vulnerability exists due to improper input validation. A local user can send a specially crafted request and elevate privileges on the system.
Affected software
TensorFlow
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Watson Discovery for IBM Cloud Pak for Data
How to mitigate CVE-2023-30767
Install updates from vendor's website.
TensorFlow - update to 2.13.0
IBM Watson Discovery for IBM Cloud Pak for Data - addressed in versions 4.8.7, 5.0.3
IBM Watson Discovery for IBM Cloud Pak for Data - addressed in versions 4.8.7, 5.0.3