Security Advisory

CVE-2024-28424

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2024-03-14 00:00:00
Last updated 2025-04-10 20:32:35
Assigner mitre
State PUBLISHED

Description

zenml v0.55.4 was discovered to contain an arbitrary file upload vulnerability in the load function at /materializers/cloudpickle_materializer.py. This vulnerability allows attackers to execute arbitrary code via uploading a crafted file.