Security Advisory

CVE-2024-27133

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2024-02-23 22:00:33
Last updated 2024-08-22 18:01:49
Assigner JFROG
CVSS score 7.5
State PUBLISHED

Description

Insufficient sanitization in MLflow leads to XSS when running a recipe that uses an untrusted dataset. This issue leads to a client-side RCE when running the recipe in Jupyter Notebook. The vulnerability stems from lack of sanitization over dataset table fields.