VYPR
Low severity3.5NVD Advisory· Published May 30, 2023· Updated Jun 17, 2026

CVE-2023-2970

CVE-2023-2970

Description

A vulnerability classified as problematic was found in MindSpore 2.0.0-alpha/2.0.0-rc1. This vulnerability affects the function JsonHelper::UpdateArray of the file mindspore/ccsrc/minddata/dataset/util/json_helper.cc. The manipulation leads to memory corruption. The name of the patch is 30f4729ea2c01e1ed437ba92a81e2fc098d608a9. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-230176.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
mindsporePyPI
<= 2.0.0-rc1

Affected products

4
  • cpe:2.3:a:mindspore:mindspore:2.0.0:alpha:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:mindspore:mindspore:2.0.0:alpha:*:*:*:*:*:*
    • cpe:2.3:a:mindspore:mindspore:2.0.0:rc1:*:*:*:*:*:*
    • (no CPE)
  • ghsa-coords
    Range: <= 2.0.0-rc1

Patches

Vulnerability mechanics

References

7

News mentions

0

No linked articles in our index yet.