tensorflow-cpu@2.11.1 vulnerabilities

TensorFlow is an open source machine learning framework for everyone.

  • latest version

    2.19.0

  • latest non vulnerable version

  • first published

    5 years ago

  • latest version published

    1 months ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the tensorflow-cpu package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • H
    Integer Overflow or Wraparound

    tensorflow-cpu is a machine learning framework.

    Affected versions of this package are vulnerable to Integer Overflow or Wraparound due to the array_ops.upper_bound function. An attacker can cause a denial of service by providing input that is not a rank 2 tensor.

    How to fix Integer Overflow or Wraparound?

    Upgrade tensorflow-cpu to version 2.12.0 or higher.

    [,2.12.0)