PT-2024-21666 · Mlflow · Mlflow

Uriya Yavnieli

·

Published

2024-02-23

·

Updated

2025-01-22

·

CVE-2024-27133

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
The issue is with MLflow, which has a problem with insufficient sanitization, leading to XSS when running a recipe that uses an untrusted dataset. This can further result in a client-side RCE when the recipe is run in Jupyter Notebook. The affected software is MLflow, and the issue arises from a lack of sanitization of dataset table fields. An exploit for this issue is available, but the specific affected versions of MLflow are not specified. The issue can be exploited when running a recipe with an untrusted dataset, leading to XSS and potentially client-side RCE in Jupyter Notebook. #MLflow #XSS #RCE #JupyterNotebook #cybersecurityawareness #infosec #hacker

Exploit

Fix

RCE

XSS

Weakness Enumeration

Related Identifiers

BIT-MLFLOW-2024-27133
CVE-2024-27133
GHSA-3V79-Q7PH-J75H
PYSEC-2024-241

Affected Products

Mlflow