Database/AI/ML frameworks & serving

ClearML fileserver: No authentication — arbitrary read/write/delete of all stored artifacts
CVE-2024-24592AI/ML frameworks & servingcurated
Impact
No authentication — arbitrary read/write/delete of all stored artifacts
Who can reach it
Unauthenticated network to the fileserver
What to do
Upgrade and front with auth. All experiment data and models are exposed
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.