Arbitrary Code Execution Vulnerability in MLflow Platform
CVE-2024-37053
8.8HIGH
What is CVE-2024-37053?
A deserialization vulnerability exists in the MLflow platform, affecting versions 1.1.0 and newer. This vulnerability allows attackers to upload malicious scikit-learn models that can run arbitrary code when interacted with by an end user. Organizations leveraging MLflow for machine learning workflows must be vigilant, as exploitation could lead to unauthorized access and execution of harmful code on affected systems. Prompt action is imperative to mitigate the risks associated with this security flaw.
Affected Version(s)
MLflow 1.1.0