Deserialization of untrusted data can occur in versions of the MLflow platform running version 2.0.0rc0 or newer, enabling a maliciously uploaded Tensorflow model to run arbitrary code on an end user’s system when interacted with.
2024-06-04T12:15:11.800
2025-02-03T14:45:23.600
Analyzed
6f8de1f0-f67e-45a6-b68f-98777fdb759c
CVSSv3.1: 8.8 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | lfprojects | mlflow | ≥ 2.0.0 | Yes |