CVE-2024-27134

CVSS V2 None CVSS V3 None
Description
Excessive directory permissions in MLflow leads to local privilege escalation when using spark_udf. This behavior can be exploited by a local attacker to gain elevated permissions by using a ToCToU attack. The issue is only relevant when the spark_udf() MLflow API is called.
Overview
  • CVE ID
  • CVE-2024-27134
  • Assigner
  • JFROG
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-11-25T13:48:05.117Z
  • Last Modified Date
  • 2024-11-25T14:23:59.324Z
References
Reference URL Reference Tags
https://github.com/mlflow/mlflow/pull/10874 patch
History
Created Old Value New Value Data Type Notes
2024-11-26 13:06:58 Added to TrackCVE