github.com
https://github.com/allegroai/clearml CVE-2024-24590
HIGH
Allegro AI ClearML vulnerable to deserialization of untrusted data
Record summary
CVE-2024-24590 has a selected CVSS score of 8.0 (high); EIP currently links 6 repository PoCs.
Description
Deserialization of untrusted data can occur in versions 0.17.0 to 1.14.2 of the client SDK of Allegro AI’s ClearML platform, enabling a maliciously uploaded artifact to run arbitrary code on an end user’s system when interacted with.
Description source: CVE List
Exploitation context
Available material
- Repository PoCs
- 6
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 8, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
ClearMLBrowse Allegro.AI / ClearMLDefault status: affected | CVE List | 0.17.0 to < 1.14.3 | affected |
clearmlBrowse PyPI / clearml | GitHub Advisory | 0.17.0 to ≤ 1.14.1 | affected |
Proofs of concept
6Repository PoCs
GitHubOxyDeV2/ClearML-CVE-2024-24590Repository PoCby OxyDeV2Stars: 6Not analyzed2 files
GitHubrippsec/CVE-2024-24590-ClearML-RCE-ExploitRepository PoCby rippsecStars: 6Not analyzed4 files
GitHubdiegogarciayala/CVE-2024-24590-ClearML-RCE-CMD-POCRepository PoCby diegogarciayalaStars: 9Not analyzed2 files
GitHubjunnythemarksman/CVE-2024-24590Repository PoCby junnythemarksmanStars: 1Not analyzed2 files
GitHubsviim/ClearML-CVE-2024-24590-RCERepository PoCby sviimStars: 4Not analyzed2 files
GitHubj3r1ch0123/CVE-2024-24590Repository PoCby j3r1ch0123Stars: 0Not analyzed2 files
References
3hiddenlayer.com
https://hiddenlayer.com/research/not-so-clear-how-mlops-solutions-can-muddy-the-waters-of-your-supply-chain nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-24590