Insecure Temporary File in transformers - CVE-2023-2800

 

Insecure Temporary File in transformers - CVE-2023-2800

Published: November 21, 2023


Vulnerability identifier: #VU83354
CSH Severity: Low
CVSS v4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-2800
CWE-ID: CWE-377
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources. A local user can trigger resource exhaustion and perform a denial of service (DoS) attack.


Affected software

transformers
Robotic Process Automation for Cloud Pak
Watson Studio on Cloud Pak for Data
Python for Scientific Computing
App Connect Enterprise Certified Container

How to mitigate CVE-2023-2800

Install updates from vendor's website.

transformers - update to 4.30.0
Python for Scientific Computing - update to 4.2.1
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.11, 23.0.12
Watson Studio on Cloud Pak for Data - update to 4.8.0
App Connect Enterprise Certified Container - addressed in versions 5.0.8, 9.0.0

External References

Related Security Bulletins