cve/2024/CVE-2024-24590.md
2024-08-10 19:04:30 +00:00

911 B
Raw Blame History

CVE-2024-24590

Description

Deserialization of untrusted data can occur in versions 0.17.0 to 1.14.2 of the client SDK of Allegro AIs ClearML platform, enabling a maliciously uploaded artifact to run arbitrary code on an end users system when interacted with.

POC

Reference

No PoCs from references.

Github