Insecure Temporary File in transformers - CVE-2023-2800
Published: November 21, 2023
Vulnerability identifier: #VU83354
CSH Severity: Low
CVSS v4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-2800
CWE-ID: CWE-377
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources. A local user can trigger resource exhaustion and perform a denial of service (DoS) attack.
Affected software
transformers
Robotic Process Automation for Cloud Pak
Watson Studio on Cloud Pak for Data
Python for Scientific Computing
App Connect Enterprise Certified Container
Robotic Process Automation for Cloud Pak
Watson Studio on Cloud Pak for Data
Python for Scientific Computing
App Connect Enterprise Certified Container
How to mitigate CVE-2023-2800
Install updates from vendor's website.
transformers - update to 4.30.0
Python for Scientific Computing - update to 4.2.1
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.11, 23.0.12
Watson Studio on Cloud Pak for Data - update to 4.8.0
App Connect Enterprise Certified Container - addressed in versions 5.0.8, 9.0.0
Python for Scientific Computing - update to 4.2.1
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.11, 23.0.12
Watson Studio on Cloud Pak for Data - update to 4.8.0
App Connect Enterprise Certified Container - addressed in versions 5.0.8, 9.0.0