CVE-2024-37059
EUVD-2024-219104.06.2024, 12:15
Deserialization of untrusted data can occur in versions of the MLflow platform running version 0.5.0 or newer, enabling a maliciously uploaded PyTorch model to run arbitrary code on an end user’s system when interacted with.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| lfprojects | mlflow | 0.5.0 ≤ |
𝑥
= Vulnerable software versions
Common Weakness Enumeration