Database/AI/ML frameworks & serving

ClearML fileserver: No authentication — arbitrary read/write/delete of all stored artifacts
CVSS 9.8CVE-2024-24592AI/ML frameworks & servingcurated
Impact
No authentication — arbitrary read/write/delete of all stored artifacts
Who can reach it
Unauthenticated network to the fileserver
What to do
Upgrade and front with auth. All experiment data and models are exposed
References
Related entries
- langchain-experimental: Second bypass of CVE-2023-44467CVE-2024-27444 · langchain-experimentalCritical
- Pure Storage FlashArray Purity API endpoint: A specific call to a FlashArray endpoint escalates the caller's privilegesCVE-2024-3057 · Pure Storage FlashArray Purity API endpointCritical
- TorchServe: `allowed_urls` bypassCVE-2024-35198 · TorchServeCritical
- Keras / TensorFlow: Arbitrary code injection in Keras < 2.13 via Lambda-layer model loadingCVE-2024-3660 · Keras / TensorFlowCritical
- Gradio: Code injection via `gradio/component_meta.py`CVE-2024-39236 · GradioCritical
- langchain-experimental: Arbitrary code execution in 0.1.17–0.3.0CVE-2024-46946 · langchain-experimentalCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.