CVE-2022-29216 (CNNVD-202205-3929)
中文标题:
Google TensorFlow代码注入漏洞
英文标题:
Code injection in `saved_model_cli` in TensorFlow
漏洞描述
中文描述:
Google TensorFlow是美国谷歌(Google)公司的一套用于机器学习的端到端开源平台。 TensorFlow 2.9.0之前版本、2.8.1之前版本、2.7.2之前版本和2.6.4之前版本存在代码注入漏洞,该漏洞源于saved_model_cli工具存在代码注入问题。
英文描述:
TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, TensorFlow's `saved_model_cli` tool is vulnerable to a code injection. This can be used to open a reverse shell. This code path was maintained for compatibility reasons as the maintainers had several test cases where numpy expressions were used as arguments. However, given that the tool is always run manually, the impact of this is still not severe. The maintainers have now removed the `safe=False` argument, so all parsing is done without calling `eval`. The patch is available in versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| tensorflow | tensorflow | < 2.6.4 | - | - |
cpe:2.3:a:tensorflow:tensorflow:<_2.6.4:*:*:*:*:*:*:*
|
| tensorflow | tensorflow | >= 2.7.0rc0, < 2.7.2 | - | - |
cpe:2.3:a:tensorflow:tensorflow:>=_2.7.0rc0,_<_2.7.2:*:*:*:*:*:*:*
|
| tensorflow | tensorflow | >= 2.8.0rc0, < 2.8.1 | - | - |
cpe:2.3:a:tensorflow:tensorflow:>=_2.8.0rc0,_<_2.8.1:*:*:*:*:*:*:*
|
| tensorflow | tensorflow | >= 2.9.0rc0, < 2.9.0 | - | - |
cpe:2.3:a:tensorflow:tensorflow:>=_2.9.0rc0,_<_2.9.0:*:*:*:*:*:*:*
|
| tensorflow | * | - | - |
cpe:2.3:a:google:tensorflow:*:*:*:*:*:*:*:*
|
|
| tensorflow | 2.7.0 | - | - |
cpe:2.3:a:google:tensorflow:2.7.0:rc0:*:*:*:*:*:*
|
|
| tensorflow | 2.8.0 | - | - |
cpe:2.3:a:google:tensorflow:2.8.0:-:*:*:*:*:*:*
|
|
| tensorflow | 2.9.0 | - | - |
cpe:2.3:a:google:tensorflow:2.9.0:rc0:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
CVSS评分详情
3.1 (cna)
HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2022-29216 |
2025-11-11 15:21:23 | 2025-11-11 07:37:29 |
| NVD | nvd_CVE-2022-29216 |
2025-11-11 14:58:18 | 2025-11-11 07:45:44 |
| CNNVD | cnnvd_CNNVD-202205-3929 |
2025-11-11 15:10:54 | 2025-11-11 07:57:18 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 代码注入
- cnnvd_id: 未提取 -> CNNVD-202205-3929
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- affected_products_count: 4 -> 8
- data_sources: ['cve'] -> ['cve', 'nvd']