You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Path to dependency file: /SuperCluster/Kali/Python/requirements.txt
Path to vulnerable library: /tmp/ws-ua_20250114023736_VDGCJZ/python_FESKPX/202501140237371/env/lib/python3.8/site-packages/keras-2.15.0.dist-info,/tmp/ws-ua_20250114023736_VDGCJZ/python_FESKPX/202501140251421/env/lib/python3.8/site-packages/keras-2.15.0.dist-info,/tmp/ws-ua_20250114023736_VDGCJZ/python_FESKPX/202501140302441/env/lib/python3.8/site-packages/keras-2.15.0.dist-info,/tmp/ws-ua_20250114023736_VDGCJZ/python_FESKPX/202501140246161/env/lib/python3.8/site-packages/keras-2.15.0.dist-info,/tmp/ws-ua_20250114023736_VDGCJZ/python_FESKPX/202501140257071/env/lib/python3.8/site-packages/keras-2.15.0.dist-info
An issue in keras 3.7.0 allows attackers to write arbitrary files to the user's machine via downloading a crafted tar file through the get_file function.
Use of vulnerable components will introduce weaknesses into the application. Components with published vulnerabilities will allow easy exploitation as resources will often be available to automate the process.
CVE-2024-55459 - Medium Severity Vulnerability
Vulnerable Library - keras-2.15.0-py3-none-any.whl
Multi-backend Keras.
Library home page: https://files.pythonhosted.org/packages/fc/a7/0d4490de967a67f68a538cc9cdb259bff971c4b5787f7765dc7c8f118f71/keras-2.15.0-py3-none-any.whl
Path to dependency file: /SuperCluster/Kali/Python/requirements.txt
Path to vulnerable library: /tmp/ws-ua_20250114023736_VDGCJZ/python_FESKPX/202501140237371/env/lib/python3.8/site-packages/keras-2.15.0.dist-info,/tmp/ws-ua_20250114023736_VDGCJZ/python_FESKPX/202501140251421/env/lib/python3.8/site-packages/keras-2.15.0.dist-info,/tmp/ws-ua_20250114023736_VDGCJZ/python_FESKPX/202501140302441/env/lib/python3.8/site-packages/keras-2.15.0.dist-info,/tmp/ws-ua_20250114023736_VDGCJZ/python_FESKPX/202501140246161/env/lib/python3.8/site-packages/keras-2.15.0.dist-info,/tmp/ws-ua_20250114023736_VDGCJZ/python_FESKPX/202501140257071/env/lib/python3.8/site-packages/keras-2.15.0.dist-info
Dependency Hierarchy:
Found in HEAD commit: 282db09a8dda8b4c4d0ff56875195546b18b0ec5
Found in base branch: master
Vulnerability Details
An issue in keras 3.7.0 allows attackers to write arbitrary files to the user's machine via downloading a crafted tar file through the get_file function.
Publish Date: 2025-01-08
URL: CVE-2024-55459
CVSS 3 Score Details (6.5)
Base Score Metrics:
Step up your Open Source Security Game with Mend here
The text was updated successfully, but these errors were encountered: