CVE-2024-28424

Publication date

2024-03-14 00:00:00

Family

mitre

State

PUBLISHED

Description

zenml v0.55.4 was discovered to contain an arbitrary file upload vulnerability in the load function at /materializers/cloudpickle_materializer.py. This vulnerability allows attackers to execute arbitrary code via uploading a crafted file.