CVE-2024-45857 - Cleanlab Deserialization RCE

2 months ago 27
ARTICLE AD BOX
CVE ID : CVE-2024-45857
Published : Sept. 12, 2024, 1:15 p.m. | 24 minutes ago
Description : Deserialization of untrusted data can occur in versions 2.4.0 or newer of the Cleanlab project, enabling a maliciously crafted datalab.pkl file to run arbitrary code on an end user’s system when the data directory is loaded.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Read Entire Article