CVE-2024-37061High· 8.8▾ TwilightMLFlow improper input validation
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 48.4 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
0.9%
Last analysed / modified upstream
Remote Code Execution can occur in versions of the MLflow platform running version 1.11.0 or newer, enabling a maliciously crafted MLproject to execute arbitrary code on an end user’s system when run due to unfiltered input.
mlflow >= 1.11.0, <= 2.13.1Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
CVE-2024-37055High· 8.8MLFlow unsafe deserialization
CVE-2024-37059High· 8.8MLFlow unsafe deserialization
CVE-2024-37057High· 8.8MLFlow unsafe deserialization
CVE-2024-37054High· 8.8MLFlow unsafe deserialization
CVE-2024-37058High· 8.8MLFlow unsafe deserialization
CVE-2024-37060High· 8.8MLFlow unsafe deserialization