Database/AI/ML frameworks & serving
BentoML: Insecure deserialization
CVE-2024-2912AI/ML frameworks & servingcurated
Impact
Insecure deserialization → RCE from a crafted POST
Who can reach it
Unauthenticated network to the BentoML serving port
What to do
Upgrade. A default BentoML service is an unauthenticated RCE endpoint pre-patch
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.