Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-2753 | Deserialization of untrusted data can occur in versions 2.4.0 or newer of the Cleanlab project, enabling a maliciously crafted datalab.pkl file to run arbitrary code on an end user’s system when the data directory is loaded. |
Github GHSA |
GHSA-8cm9-rrgc-4pcj | Cleanlab Deserialization of Untrusted Data vulnerability |
Thu, 12 Sep 2024 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cleanlab
Cleanlab cleanlab |
|
| CPEs | cpe:2.3:a:cleanlab:cleanlab:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Cleanlab
Cleanlab cleanlab |
|
| Metrics |
ssvc
|
Thu, 12 Sep 2024 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Deserialization of untrusted data can occur in versions 2.4.0 or newer of the Cleanlab project, enabling a maliciously crafted datalab.pkl file to run arbitrary code on an end user’s system when the data directory is loaded. | |
| Weaknesses | CWE-502 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: HiddenLayer
Published:
Updated: 2024-09-12T14:43:45.118Z
Reserved: 2024-09-10T15:36:55.926Z
Link: CVE-2024-45857
Updated: 2024-09-12T14:43:40.591Z
Status : Deferred
Published: 2024-09-12T13:15:16.227
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-45857
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA