Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.1.0 or newer, enabling a maliciously uploaded scikit-learn model to run arbitrary code on an end user’s system when interacted with.
2024-06-04T12:15:10.413
2025-02-03T14:35:02.407
Analyzed
6f8de1f0-f67e-45a6-b68f-98777fdb759c
CVSSv3.1: 8.8 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | lfprojects | mlflow | ≥ 1.1.0 | Yes |