Security Advisory

CVE-2024-37057

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2024-06-04 12:01:28
Last updated 2024-08-02 03:43:51
Assigner HiddenLayer
CVSS score 8.8
State PUBLISHED

Description

Deserialization of untrusted data can occur in versions of the MLflow platform running version 2.0.0rc0 or newer, enabling a maliciously uploaded Tensorflow model to run arbitrary code on an end user’s system when interacted with.