CVE-2024-27133

Insufficient sanitization in MLflow leads to XSS when running a recipe that uses an untrusted dataset. This issue leads to a client-side RCE when running the recipe in Jupyter Notebook. The vulnerability stems from lack of sanitization over dataset table fields.
Configurations

Configuration 1 (hide)

cpe:2.3:a:lfprojects:mlflow:*:*:*:*:*:*:*:*

History

22 Jan 2025, 13:46

Type Values Removed Values Added
First Time Lfprojects
Lfprojects mlflow
References () https://github.com/mlflow/mlflow/pull/10893 - () https://github.com/mlflow/mlflow/pull/10893 - Issue Tracking, Patch
References () https://research.jfrog.com/vulnerabilities/mlflow-untrusted-dataset-xss-jfsa-2024-000631932/ - () https://research.jfrog.com/vulnerabilities/mlflow-untrusted-dataset-xss-jfsa-2024-000631932/ - Exploit, Third Party Advisory
CPE cpe:2.3:a:lfprojects:mlflow:*:*:*:*:*:*:*:*

21 Nov 2024, 09:03

Type Values Removed Values Added
Summary
  • (es) Una sanitización insuficiente en MLflow genera XSS cuando se ejecuta una receta que utiliza un conjunto de datos que no es de confianza. Este problema provoca un RCE del lado del cliente al ejecutar la receta en Jupyter Notebook. La vulnerabilidad se debe a la falta de saneamiento de los campos de la tabla del conjunto de datos.
References () https://github.com/mlflow/mlflow/pull/10893 - () https://github.com/mlflow/mlflow/pull/10893 -
References () https://research.jfrog.com/vulnerabilities/mlflow-untrusted-dataset-xss-jfsa-2024-000631932/ - () https://research.jfrog.com/vulnerabilities/mlflow-untrusted-dataset-xss-jfsa-2024-000631932/ -

23 Feb 2024, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-23 22:15

Updated : 2025-01-22 13:46


NVD link : CVE-2024-27133

Mitre link : CVE-2024-27133

CVE.ORG link : CVE-2024-27133


JSON object : View

Products Affected

lfprojects

  • mlflow
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')