Description
Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.23.0 or newer, enabling a maliciously uploaded LightGBM scikit-learn model to run arbitrary code on an end user’s system when interacted with.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-1966 | Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.23.0 or newer, enabling a maliciously uploaded LightGBM scikit-learn model to run arbitrary code on an end user’s system when interacted with. |
Github GHSA |
GHSA-7p8j-qv6x-f4g4 | MLFlow unsafe deserialization |
References
History
Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Mon, 03 Feb 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Lfprojects
Lfprojects mlflow |
|
| CPEs | cpe:2.3:a:lfprojects:mlflow:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Lfprojects
Lfprojects mlflow |
Status: PUBLISHED
Assigner: HiddenLayer
Published:
Updated: 2024-08-02T03:43:50.908Z
Reserved: 2024-05-31T14:16:48.807Z
Link: CVE-2024-37056
Updated: 2024-08-02T03:43:50.908Z
Status : Analyzed
Published: 2024-06-04T12:15:11.593
Modified: 2025-02-03T14:45:07.183
Link: CVE-2024-37056
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA