Arbitrary Code Execution Vulnerability in Allegro AI's ClearML Platform
CVE-2024-24590
Key Information:
- Vendor
Allegro.AI
- Status
- Vendor
- CVE Published:
- 6 February 2024
Badges
What is CVE-2024-24590?
Versions 0.17.0 to 1.14.2 of Allegro AI's ClearML Client SDK are susceptible to a deserialization vulnerability that allows untrusted data to be executed as code. This weakness facilitates the execution of arbitrary code when an end user interacts with a maliciously uploaded artifact, posing significant security risks to the integrity of user systems. Users are advised to assess their SDK versions and implement appropriate measures to mitigate this vulnerability.
Affected Version(s)
ClearML 0.17.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
EPSS Score
75% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved