Remote Code Execution can occur in versions of the MLflow platform running version 1.11.0 or newer, enabling a maliciously crafted MLproject to execute arbitrary code on an end user’s system when run.
2024-06-04T12:15:12.703
2025-02-03T14:48:37.123
Analyzed
6f8de1f0-f67e-45a6-b68f-98777fdb759c
CVSSv3.1: 8.8 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | lfprojects | mlflow | ≥ 1.11.0 | Yes |