Arbitrary Code Execution Vulnerability in MLflow Platform
CVE-2024-37057

8.8HIGH

Key Information:

Vendor
Mlflow
Status
Vendor
CVE Published:
4 June 2024

Summary

A deserialization vulnerability exists in the MLflow platform, affecting versions 2.0.0rc0 and later. This flaw could allow a malicious actor to upload a compromised Tensorflow model. If an end user interacts with this model, it may result in arbitrary code execution on their system. This vulnerability underscores the importance of secure handling of untrusted data within machine learning workflows.

Affected Version(s)

MLflow 2.0.0rc0

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.