-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability CVE-2024-37060 specifically references unsafe deserialization in the BaseCard.load method within recipes/cards/init.py. The code snippet shows direct use of pickle.load() on user-controlled file paths, with no validation or safe deserialization mechanisms. This matches the CWE-502 pattern and the advisory's description of Recipe-based exploitation. Other CVEs in the advisory relate to different components (sklearn, pyfunc, etc.), but this entry specifically implicates the BaseCard.load method as the vulnerable entry point for this particular CVE.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| mlflow | pip | >= 1.27.0, <= 2.14.1 |
Ongoing coverage of React2Shell