CVE-2023-7018

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Dec 20, 2023
Updated: Dec 30, 2023
CWE ID 502

Summary

CVE-2023-7018 is a high severity vulnerability in the GitHub repository huggingface/transformers prior to version 4.36, affecting various products such as rX2lzA, rX2lzB, rX2lyQ, and t81Db_. This vulnerability is related to the deserialization of untrusted data and has a risk score of 28. It requires user interaction and can be exploited locally. The potential danger to organizations is significant as it can lead to high impact on confidentiality and integrity of data. To remediate this vulnerability, it is recommended to update the affected products to version 4.36 or above.

Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Prioritize, Pinpoint, and Act to Prevent Vulnerability Exploits with Recorded Future

Note: This is just a basic overview providing quick insights into CVE-2023-7018 information. Gain full access to comprehensive CVE data, third party vulnerabilities, compromised credentials and more with Recorded Future
  • Gain complete coverage of your cyber, third party, and physical attack surface
  • Proactively mitigate threats before they turn into costly attacks
  • Make fast, effective, data-driven decisions