CVE-2024-37054
Deserialization of untrusted data can occur in versions of the MLflow platform running version 0.9.0 or newer, enabling a maliciously uploaded PyFunc model to run arbitrary code on an end user’s system when interacted with.
- Affected products
- Mlflow
- Lfprojects Mlflow
- All versions
- CVSS 3.1
- 8.8 HIGH
- EPSS
- 0.7% (51th percentile)
- Weakness
- CWE-502
- NVD status
- Analyzed
- Published
- 2024-06-04
- Attack patterns
- CAPEC-586
- Entry point
- file request body
- Path
- models.smarthire.htb/predict
CVE-2024-37054 at NVD
10 known exploits for CVE-2024-37054
Proof-of-concept code and exploit modules indexed by Sploitus
CVE-2024-37054-MLflow-RCE
CVE-2024-37054
CVE-2024-37054-MLflow-reverse-shell
CVE-2024-37054-PoC
CVE-2024-37054
Exploit for Deserialization of Untrusted Data in Lfprojects Mlflow
Exploit for Deserialization of Untrusted Data in Lfprojects Mlflow
Exploit for Deserialization of Untrusted Data in Lfprojects Mlflow
Exploit for Deserialization of Untrusted Data in Lfprojects Mlflow
Exploit for Deserialization of Untrusted Data in Lfprojects Mlflow