PT-2024-4085 · Unknown+1 · Jupyter Notebook+1
Uriya Yavnieli
·
Published
2024-02-23
·
Updated
2025-01-22
·
CVE-2024-27132
CVSS v3.1
9.6
Critical
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
MLflow versions prior to 2.4.1
Description
The issue stems from insufficient sanitization in MLflow, leading to cross-site scripting (XSS) when running an untrusted recipe. This can be escalated to a client-side remote code execution (RCE) when running the recipe via Jupyter Notebook. The vulnerability is due to a lack of sanitization over template variables.
Recommendations
To protect against remote code execution, update to version 2.4.1. As a temporary workaround, consider restricting the use of untrusted recipes in Jupyter Notebook until the issue is resolved. Avoid running untrusted recipes to minimize the risk of exploitation.
Exploit
Fix
RCE
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jupyter Notebook
Mlflow