Description
Deserialization of untrusted data can occur in versions 2.4.0 or newer of the Cleanlab project, enabling a maliciously crafted datalab.pkl file to run arbitrary code on an end user’s system when the data directory is loaded.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-2753 | Deserialization of untrusted data can occur in versions 2.4.0 or newer of the Cleanlab project, enabling a maliciously crafted datalab.pkl file to run arbitrary code on an end user’s system when the data directory is loaded. |
Github GHSA |
GHSA-8cm9-rrgc-4pcj | Cleanlab Deserialization of Untrusted Data vulnerability |
References
History
Thu, 12 Sep 2024 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cleanlab
Cleanlab cleanlab |
|
| CPEs | cpe:2.3:a:cleanlab:cleanlab:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Cleanlab
Cleanlab cleanlab |
|
| Metrics |
ssvc
|
Thu, 12 Sep 2024 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Deserialization of untrusted data can occur in versions 2.4.0 or newer of the Cleanlab project, enabling a maliciously crafted datalab.pkl file to run arbitrary code on an end user’s system when the data directory is loaded. | |
| Weaknesses | CWE-502 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: HiddenLayer
Published:
Updated: 2024-09-12T14:43:45.118Z
Reserved: 2024-09-10T15:36:55.926Z
Link: CVE-2024-45857
Updated: 2024-09-12T14:43:40.591Z
Status : Deferred
Published: 2024-09-12T13:15:16.227
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-45857
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA