cve/2024/CVE-2024-24591.md
2024-05-25 21:48:12 +02:00

839 B
Raw Blame History

CVE-2024-24591

Description

A path traversal vulnerability in versions 1.4.0 to 1.14.1 of the client SDK of Allegro AIs ClearML platform enables a maliciously uploaded dataset to write local or remote files to an arbitrary location on an end users system when interacted with.

POC

Reference

No PoCs from references.

Github