CVE Radar Logo
CVERadar
CVE Radar Logo
CVERadar

CVE-2024-24590

Critical Severity
Clear
SVRS
85/100

CVSSv3
8.8/10

EPSS
0.75066/1

CVE-2024-24590 poses a critical security risk in Allegro AI's ClearML client SDK. This vulnerability allows for deserialization of untrusted data, potentially enabling attackers to execute arbitrary code on a user's system through maliciously crafted artifacts. With an extremely high SOCRadar Vulnerability Risk Score (SVRS) of 85, this CVE demands immediate attention and remediation. The vulnerability affects versions 0.17.0 to 1.14.2 of the ClearML client SDK. The high SVRS score is due to factors such as active exploits being available and the vulnerability being observed "In The Wild" adding urgency beyond its CVSS score. Successfully exploiting this CVE could lead to complete system compromise, data breaches, and significant operational disruption. Organizations using affected versions of ClearML should prioritize patching or implementing mitigating controls to prevent exploitation.

In The Wild
Exploit Avaliable
CVSS:3.1
AV:N
AC:L
PR:N
UI:R
S:U
C:H
I:H
A:H
2024-02-06

2024-02-15

Indicators of Compromise

No IOCs found for this CVE

Exploits

TitleSoftware LinkDate
diegogarciayala/CVE-2024-24590-ClearML-RCE-CMD-POChttps://github.com/diegogarciayala/CVE-2024-24590-ClearML-RCE-CMD-POC2024-06-15
h3xm4n/ClearML-vulnerability-exploit-RCE-2024-CVE-2024-24590-https://github.com/h3xm4n/ClearML-vulnerability-exploit-RCE-2024-CVE-2024-24590-2024-06-11
j3r1ch0123/CVE-2024-24590https://github.com/j3r1ch0123/CVE-2024-245902024-10-07
LordVileOnX/ClearML-vulnerability-exploit-RCE-2024-CVE-2024-24590-https://github.com/LordVileOnX/ClearML-vulnerability-exploit-RCE-2024-CVE-2024-24590-2024-06-11
xffsec/CVE-2024-24590-ClearML-RCE-Exploithttps://github.com/xffsec/CVE-2024-24590-ClearML-RCE-Exploit2024-06-13
DemonPandaz2763/CVE-2024-24590https://github.com/DemonPandaz2763/CVE-2024-245902024-06-12
sviim/ClearML-CVE-2024-24590-RCEhttps://github.com/sviim/ClearML-CVE-2024-24590-RCE2024-07-21
Enhance Your CVE Management with SOCRadar Vulnerability Intelligence
Get comprehensive CVE details, real-time notifications, and proactive threat management all in one platform.
CVE Details
Access comprehensive CVE information instantly
Real-time Tracking
Subscribe to CVEs and get instant updates
Exploit Analysis
Monitor related APT groups and threats
IOC Tracking
Analyze and track CVE-related IOCs

News

No news found for this CVE

Social Media

GitHub - OxyDeV2/PoC-CVE-2024-24590: Proof of concept for CVE-2024-24590 - https://t.co/d93ZG57ehM
0
0
2

Affected Software

Configuration 1
TypeVendorProduct
AppClearclearml

References

ReferenceLink
6F8DE1F0-F67E-45A6-B68F-98777FDB759Chttps://hiddenlayer.com/research/not-so-clear-how-mlops-solutions-can-muddy-the-waters-of-your-supply-chain/

CWE Details

CWE IDCWE NameDescription
CWE-502Deserialization of Untrusted DataThe application deserializes untrusted data without sufficiently verifying that the resulting data will be valid.

CVE Radar

Real-time CVE Intelligence & Vulnerability Management Platform

CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.

Get Free Vulnerability Intelligence AccessAccess real-time CVE monitoring, exploit analysis, and threat intelligence