CVE-2024-37060High· 8.8▾ TwilightMLFlow unsafe deserialization
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 48.4 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.8%
0.8% → 0.8%
Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.27.0 or newer, enabling a maliciously crafted Recipe to execute arbitrary code on an end user’s system when run.
mlflow >= 1.27.0, <= 2.14.1Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
CVE-2024-37055High· 8.8MLFlow unsafe deserialization
CVE-2024-37059High· 8.8MLFlow unsafe deserialization
CVE-2024-37061High· 8.8MLFlow improper input validation
CVE-2024-37057High· 8.8MLFlow unsafe deserialization
CVE-2024-37054High· 8.8MLFlow unsafe deserialization
CVE-2024-37058High· 8.8MLFlow unsafe deserialization