PT-2024-20472 · Allegro Ai · Clearml

Published

2024-02-06

·

Updated

2025-07-29

·

CVE-2024-24590

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Allegro AI’s ClearML platform versions 0.17.0 through 1.14.2
Description Deserialization of untrusted data can occur in the client SDK of Allegro AI’s ClearML platform, enabling a maliciously uploaded artifact to run arbitrary code on an end user’s system when interacted with.
Recommendations For versions 0.17.0 through 1.14.2, consider disabling the deserialization of untrusted data as a temporary workaround until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2024-24590
GHSA-CPCW-9H9M-WQW9

Affected Products

Clearml