logo
Vulnerability feed
CONTRIBUTE

Vulnerability

warn

CVE-2024-27133

Reference to the description:

https://nvd.nist.gov/vuln/detail/CVE-2024-27133

Description:
Insufficient sanitization in MLflow leads to XSS when running a recipe that uses an untrusted dataset. This issue leads to a client-side RCE when running the recipe in Jupyter Notebook. The vulnerability stems from lack of sanitization over dataset table fields.
Last updated date:
01/22/2025
Type:
exploit
Confidence:
HIGH
Date of publishing:
01/22/2025
Reference url to background

https://research.jfrog.com/vulnerabilities/mlflow-untrusted-dataset-xss-jfsa-2024-000631932/

Vulnerability FeedContributorsAboutBlog

@inTheWild

©2025

Privacy Policy