CVE-2024-24590

CVSS V2 None CVSS V3 None
Description
Deserialization of untrusted data can occur in versions 0.17.0 to 1.14.2 of the client SDK of Allegro AI’s ClearML platform, enabling a maliciously uploaded artifact to run arbitrary code on an end user’s system when interacted with.
Overview
  • CVE ID
  • CVE-2024-24590
  • Assigner
  • HiddenLayer
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-02-06T14:40:26.963Z
  • Last Modified Date
  • 2024-02-13T19:51:09.693Z
History
Created Old Value New Value Data Type Notes
2024-06-26 04:18:50 Added to TrackCVE