CVE-2024-37061
EUVD-2024-212504.06.2024, 12:15
Remote Code Execution can occur in versions of the MLflow platform running version 1.11.0 or newer, enabling a maliciously crafted MLproject to execute arbitrary code on an end user’s system when run.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| lfprojects | mlflow | * ≤ 𝑥 ≤ * |
| lfprojects | mlflow | 1.11.0 ≤ |
𝑥
= Vulnerable software versions