Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-0115 | Excessive directory permissions in MLflow leads to local privilege escalation when using spark_udf. This behavior can be exploited by a local attacker to gain elevated permissions by using a ToCToU attack. The issue is only relevant when the spark_udf() MLflow API is called. |
Github GHSA |
GHSA-qpgc-w4mg-6v92 | MLflow's excessive directory permissions allow local privilege escalation |
| Link | Providers |
|---|---|
| https://github.com/mlflow/mlflow/pull/10874 |
|
Mon, 03 Feb 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:lfprojects:mlflow:*:*:*:*:*:*:*:* |
Mon, 25 Nov 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Lfprojects
Lfprojects mlflow |
|
| CPEs | cpe:2.3:a:lfprojects:mlflow:-:*:*:*:*:*:*:* | |
| Vendors & Products |
Lfprojects
Lfprojects mlflow |
|
| Metrics |
ssvc
|
Mon, 25 Nov 2024 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Excessive directory permissions in MLflow leads to local privilege escalation when using spark_udf. This behavior can be exploited by a local attacker to gain elevated permissions by using a ToCToU attack. The issue is only relevant when the spark_udf() MLflow API is called. | |
| Title | Excessive directory permissions in MLflow leads to local privilege escalation when using spark_udf | |
| Weaknesses | CWE-276 CWE-367 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: JFROG
Published:
Updated: 2024-11-25T14:23:59.324Z
Reserved: 2024-02-20T11:10:51.335Z
Link: CVE-2024-27134
Updated: 2024-11-25T14:23:53.801Z
Status : Analyzed
Published: 2024-11-25T14:15:06.867
Modified: 2025-02-03T15:05:50.187
Link: CVE-2024-27134
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA