High Severity Vulnerability
This vulnerability has been rated as High severity. Immediate action is recommended.
CVE-2024-37059
HighVulnerability Description
Deserialization of untrusted data can occur in versions of the MLflow platform running version 0.5.0 or newer, enabling a maliciously uploaded PyTorch model to run arbitrary code on an end user’s system when interacted with.
CVSS Metrics
Common Vulnerability Scoring System
Vector String:
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Known Affected Software
128 configuration(s) from 1 vendor(s)
cpe:2.3:a:lfprojects:mlflow:3.5.0:-:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:2.4.1:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:3.2.0:-:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:2.11.0:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:2.2.1:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:1.11.0:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:0.6.0:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:3.1.2:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:2.11.1:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:2.13.1:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:3.1.1:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:2.1.1:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:2.10.1:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:1.30.0:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:2.15.0:-:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:1.17.0:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:1.25.1:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:1.29.0:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:1.28.0:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:1.13.1:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:1.10.0:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:2.8.0:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:1.26.0:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:1.9.1:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:3.3.2:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:2.1.0:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:2.19.0:rc0:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:1.12.0:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:2.14.2:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:0.5.2:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:1.5.0:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:2.2.2:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:1.14.1:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:1.20.2:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:0.9.0:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:1.8.0:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:2.12.2:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:2.11.2:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:2.2.0:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:2.13.0:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:2.22.0:-:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:0.5.1:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:2.17.2:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:3.1.3:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:3.3.0:-:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:2.21.1:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:2.9.0:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:2.17.0:rc0:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:1.23.1:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:2.18.0:rc0:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:1.27.0:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:3.6.0:rc1:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:2.14.3:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:2.15.1:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:3.5.1:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:2.14.1:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:2.20.1:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:2.3.1:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:1.20.1:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:2.16.1:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:0.5.0:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:2.20.0:-:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:2.10.0:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:2.10.2:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:2.16.0:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:1.9.0:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:2.5.0:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:2.3.0:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:1.21.0:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:2.22.1:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:1.14.0:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:1.23.0:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:1.22.0:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:2.4.2:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:3.0.0:-:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:1.3.0:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:2.0.0:-:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:1.12.1:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:1.19.0:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:2.9.2:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:3.3.1:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:2.21.2:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:2.11.3:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:0.8.1:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:0.7.0:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:2.7.1:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:3.4.0:-:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:2.20.2:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:2.17.1:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:1.16.0:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:1.7.0:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:2.14.0:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:0.7:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:2.20.3:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:2.9.1:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:1.20.0:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:2.6.0:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:2.12.1:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:1.7.1:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:2.21.3:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:0.8.0:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:1.1.0:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:0.8.2:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:1.2.0:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:1.13.0:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:3.1.0:-:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:2.8.1:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:1.6.0:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:2.22.2:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:1.18.0:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:1.24.0:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:2.13.2:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:3.1.4:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:0.9.1:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:3.0.1:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:1.26.1:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:1.25.0:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:2.20.4:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:2.0.1:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:2.16.2:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:1.7.2:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:1.15.0:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:2.3.2:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:2.21.0:-:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:2.4.0:*:*:*:*:*:*:*
cpe:2.3:a:lfprojects:mlflow:2.7.0:*:*:*:*:*:*:*
CPUAPR2026
Oracle Critical Patch Update Advisory - April 2026
Severity Details
Weakness Type (CWE)
Deserialization of Untrusted Data
- Description
- The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
- Exploit Likelihood
- Medium
- Typical Severity
- Medium
- OWASP Top 10
- A08:2021-Software/Data Integrity Failures
- Abstraction Level
- Base
Key Information
- Published Date
- June 04, 2024
