PT-2024-27270 · Mlflow · Mlflow

Published

2024-06-04

·

Updated

2025-02-03

·

CVE-2024-37055

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MLflow versions 1.24.0 and newer
Description The issue allows deserialization of untrusted data, enabling a maliciously uploaded pmdarima model to run arbitrary code on an end user's system when interacted with.
Recommendations For versions 1.24.0 and newer, consider restricting the upload and interaction of pmdarima models until a fix is available. As a temporary workaround, avoid using the deserialization feature for untrusted data.

Exploit

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-MLFLOW-2024-37055
CVE-2024-37055
GHSA-X38X-G6GR-JQFF

Affected Products

Mlflow