CVE-2024-27134

Excessive directory permissions in MLflow leads to local privilege escalation when using spark_udf. This behavior can be exploited by a local attacker to gain elevated permissions by using a ToCToU attack. The issue is only relevant when the spark_udf() MLflow API is called.
References
Link Resource
https://github.com/mlflow/mlflow/pull/10874 Issue Tracking Patch
Configurations

Configuration 1 (hide)

cpe:2.3:a:lfprojects:mlflow:*:*:*:*:*:*:*:*

History

03 Feb 2025, 15:05

Type Values Removed Values Added
First Time Lfprojects mlflow
Lfprojects
References () https://github.com/mlflow/mlflow/pull/10874 - () https://github.com/mlflow/mlflow/pull/10874 - Issue Tracking, Patch
CPE cpe:2.3:a:lfprojects:mlflow:*:*:*:*:*:*:*:*

Information

Published : 2024-11-25 14:15

Updated : 2025-02-03 15:05


NVD link : CVE-2024-27134

Mitre link : CVE-2024-27134

CVE.ORG link : CVE-2024-27134


JSON object : View

Products Affected

lfprojects

  • mlflow
CWE
CWE-276

Incorrect Default Permissions

CWE-367

Time-of-check Time-of-use (TOCTOU) Race Condition