CVE-2025-0508
MEDIUMSageMaker Workflow - Info Disclosure
Title source: llmDescription
A vulnerability in the SageMaker Workflow component of aws/sagemaker-python-sdk allows for the possibility of MD5 hash collisions in all versions. This can lead to workflows being inadvertently replaced due to the reuse of results from different configurations that produce the same MD5 hash. This issue can cause integrity problems within the pipeline, potentially leading to erroneous processing outcomes.
Scores
CVSS v3
5.9
EPSS
0.0005
EPSS Percentile
16.4%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Classification
CWE
CWE-328
Status
draft
Affected Products (1)
pypi/sagemaker
< 2.237.3PyPI
Timeline
Published
Mar 20, 2025
Tracked Since
Feb 18, 2026