CVE-2024-24590

Deserialization of untrusted data can occur in versions 0.17.0 to 1.14.2 of the client SDK of Allegro AI’s ClearML platform, enabling a maliciously uploaded artifact to run arbitrary code on an end user’s system when interacted with.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:clear:clearml:*:*:*:*:*:*:*:*

History

15 Feb 2024, 15:43

Type Values Removed Values Added
References () https://hiddenlayer.com/research/not-so-clear-how-mlops-solutions-can-muddy-the-waters-of-your-supply-chain/ - () https://hiddenlayer.com/research/not-so-clear-how-mlops-solutions-can-muddy-the-waters-of-your-supply-chain/ - Exploit, Technical Description, Third Party Advisory
First Time Clear
Clear clearml
CVSS v2 : unknown
v3 : 8.0
v2 : unknown
v3 : 8.8
CPE cpe:2.3:a:clear:clearml:*:*:*:*:*:*:*:*

13 Feb 2024, 20:15

Type Values Removed Values Added
Summary
  • (es) La deserialización de datos que no son de confianza puede ocurrir en la versión 0.17.0 o posterior de la plataforma ClearML de Allegro AI, lo que permite que un artefacto cargado maliciosamente ejecute código arbitrario en el sistema de un usuario final cuando interactúa con él.
Summary (en) Deserialization of untrusted data can occur in version 0.17.0 or newer of Allegro AI’s ClearML platform, enabling a maliciously uploaded artifact to run arbitrary code on an end user’s system when interacted with. (en) Deserialization of untrusted data can occur in versions 0.17.0 to 1.14.2 of the client SDK of Allegro AI’s ClearML platform, enabling a maliciously uploaded artifact to run arbitrary code on an end user’s system when interacted with.

06 Feb 2024, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-06 15:15

Updated : 2024-02-15 15:43


NVD link : CVE-2024-24590

Mitre link : CVE-2024-24590

CVE.ORG link : CVE-2024-24590


JSON object : View

Products Affected

clear

  • clearml
CWE
CWE-502

Deserialization of Untrusted Data