CVE-2024-28424: Code Injection
zenml v0.55.4 was discovered to contain an arbitrary file upload vulnerability in the load function at /materializers/cloudpicklematerializer.py. This vulnerability allows attackers to execute arbitrary code via uploading a crafted file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-28424?
CVE-2024-28424 is classified as a high-severity vulnerability due to its potential for arbitrary code execution.
What systems are affected by CVE-2024-28424?
CVE-2024-28424 affects ZenML version 0.55.4 specifically concerning its cloudpickle materializer functionality.
How do I fix CVE-2024-28424?
To remediate CVE-2024-28424, it is recommended to upgrade to a patched version of ZenML that addresses this arbitrary file upload vulnerability.
What type of attack can exploit CVE-2024-28424?
CVE-2024-28424 can be exploited through arbitrary file uploads, allowing an attacker to execute malicious code on the server.
Is CVE-2024-28424 present in earlier versions of ZenML?
CVE-2024-28424 has been identified in ZenML version 0.55.4, and earlier versions may also be susceptible depending on their configuration.