Launch Week Day 1: Announcing Security Design Review
HIGH 7.0 PyPI

MLflow's excessive directory permissions allow local privilege escalation

GHSA-qpgc-w4mg-6v92 · BIT-mlflow-2024-27134 · CVE-2024-27134 · PYSEC-2024-224

Published · Modified

Description

Excessive directory permissions in MLflow leads to local privilege escalation when using spark_udf. This behavior can be exploited by a local attacker to gain elevated permissions by using a ToCToU attack. The issue is only relevant when the spark_udf() MLflow API is called.

Ready to move

Start Securing

Free, no credit card | First findings in minutes