Arbitrary Code Execution Vulnerability in MLflow Platform
CVE-2024-37057
8.8HIGH
Summary
A deserialization vulnerability exists in the MLflow platform, affecting versions 2.0.0rc0 and later. This flaw could allow a malicious actor to upload a compromised Tensorflow model. If an end user interacts with this model, it may result in arbitrary code execution on their system. This vulnerability underscores the importance of secure handling of untrusted data within machine learning workflows.
Affected Version(s)
MLflow 2.0.0rc0
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved