PT-2024-4085 · Unknown+1 · Jupyter Notebook+1

Uriya Yavnieli

·

Published

2024-02-23

·

Updated

2025-01-22

·

CVE-2024-27132

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MLflow versions prior to 2.4.1
Description The issue stems from insufficient sanitization in MLflow, leading to cross-site scripting (XSS) when running an untrusted recipe. This can be escalated to a client-side remote code execution (RCE) when running the recipe via Jupyter Notebook. The vulnerability is due to a lack of sanitization over template variables.
Recommendations To protect against remote code execution, update to version 2.4.1. As a temporary workaround, consider restricting the use of untrusted recipes in Jupyter Notebook until the issue is resolved. Avoid running untrusted recipes to minimize the risk of exploitation.

Exploit

Fix

RCE

XSS

Weakness Enumeration

Related Identifiers

BDU:2024-04534
BIT-MLFLOW-2024-27132
CVE-2024-27132
GHSA-6749-M5CP-6CG7
PYSEC-2024-240

Affected Products

Jupyter Notebook
Mlflow