Database/AI/ML frameworks & serving
MLflow (`_create_model_version`): Path traversal in model-version creation
CVSS 7.5CVE-2024-1558AI/ML frameworks & servingcurated
Impact
Path traversal in model-version creation
Who can reach it
Authenticated or unauthenticated model registration
What to do
Upgrade
References
Related entries
- Gradio (`/component_server`): Arbitrary method invocation on componentsCVE-2024-1561 · Gradio (`/component_server`)High
- Gradio: Local file inclusion via improper input validationCVE-2024-1728 · GradioHigh
- ONNX: Directory traversal in `external_data` — bypass of the 1.13 fixCVE-2024-27318 · ONNXHigh
- joblib (`NumpyArrayWrapper.read_array`): Deserialization vulnerability in joblib 1.4.2CVE-2024-34997 · joblib (`NumpyArrayWrapper.read_array`)High
- Jupyter Server (Windows): Unauthenticated attackers can leak the NTLM hash of the hostCVE-2024-35178 · Jupyter Server (Windows)High
- Ollama: File-existence disclosure via `api/create`CVE-2024-39719 · OllamaHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.