PT-2024-25684 · Amazon · Sagemaker-Python-Sdk

·

CVE-2024-34073

·

Published

2024-05-03

·

Updated

2026-07-07

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions sagemaker-python-sdk versions prior to 2.214.3
Description The capture dependencies function in the sagemaker.serve.save retrive.version 1 0 0.save.utils module allows for potentially unsafe Operating System (OS) Command Injection if an inappropriate command is passed as the requirements path parameter. This may allow an unprivileged third party to cause remote code execution, denial of service, affecting both confidentiality and integrity.
Recommendations For versions prior to 2.214.3, upgrade to version 2.214.3 or later. As a temporary workaround for users unable to upgrade, do not override the requirements path parameter of the capture dependencies function in sagemaker.serve.save retrive.version 1 0 0.save.utils, and instead use the default value.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-34073
GHSA-7PC3-PR3Q-58VG
PYSEC-2026-1887

Affected Products

Sagemaker-Python-Sdk