CVE-2024-37060
EUVD-2024-202904.06.2024, 12:15
Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.27.0 or newer, enabling a maliciously crafted Recipe to execute arbitrary code on an end user’s system when run.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| lfprojects | mlflow | * ≤ 𝑥 ≤ * |
| lfprojects | mlflow | 1.27.0 ≤ |
𝑥
= Vulnerable software versions
Common Weakness Enumeration