Forscher decken Schwachstellen in beliebten Open-Source-Frameworks für maschinelles Lernen auf

Teilen:

Cybersecurity researchers have disclosed multiple security flaws impacting open-source machine learning (ML) tools and frameworks such as MLflow, H2O, PyTorch, and MLeap that could pave the way for code execution.

The vulnerabilities, discovered by JFrog, are part of a broader collection of 22 security shortcomings the supply chain security company first disclosed last month.

Unlike the first set that involved flaws on the server-side, the newly detailed ones allow exploitation of ML clients and reside in libraries that handle safe model formats like Safetensors.

“Hijacking an ML client in an organization can allow the attackers to perform extensive lateral movement within the organization,” the company said. “An ML client is very likely to have access to important ML services such as ML Model Registries or MLOps Pipelines.”

This, in turn, could expose sensitive information such as model registry credentials, effectively permitting a malicious actor to backdoor stored ML models or achieve code execution.

The list of vulnerabilities is below –

  • CVE-2024-27132 (CVSS score: 7.2) – An insufficient sanitization issue in MLflow that leads to a cross-site scripting (XSS) attack when running an untrusted recipe in a Jupyter Notebook, ultimately resulting in client-side remote code execution (RCE)
  • CVE-2024-6960 (CVSS score: 7.5) – An unsafe deserialization issue in H20 when importing an untrusted ML model, potentially resulting in RCE
  • A path traversal issue in PyTorch’s TorchScript feature that could result in denial-of-service (DoS) or code execution due to arbitrary file overwrite, which could then be used to overwrite critical system files or a legitimate pickle file (No CVE identifier)
  • CVE-2023-5245 (CVSS score: 7.5) – A path traversal issue in MLeap when loading a saved model in zipped format can lead to a Zip Slip vulnerability, resulting in arbitrary file overwrite and potential code execution

JFrog noted that ML models shouldn’t be blindly loaded even in cases where they are loaded from a safe type, such as Safetensors, as they have the capability to achieve arbitrary code execution.

“AI and Machine Learning (ML) tools hold immense potential for innovation, but can also open the door for attackers to cause widespread damage to any organization,” Shachar Menashe, JFrog’s VP of Security Research, said in a statement.

“To safeguard against these threats, it’s important to know which models you’re using and never load untrusted ML models even from a ‘safe’ ML repository. Doing so can lead to remote code execution in some scenarios, causing extensive harm to your organization.”

Quelle

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
12:57 pm, Apr. 22, 2025
Wetter-Symbol 16°C
L: 14° | H: 17°
aufgelockerte Bewölkung
Luftfeuchtigkeit: 53 %
Druck: 1017 mb
Wind: 9 mph SW
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 40%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 5:49 am
Sonnenuntergang: 8:07 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
14° | 17°°C 0 mm 0% 11 mph 76 % 1017 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
8° | 11°°C 1 mm 100% 12 mph 94 % 1018 mb 0 mm/h
Do. Apr. 24 10:00 pm
Wetter-Symbol
8° | 16°°C 0.71 mm 71% 5 mph 91 % 1023 mb 0 mm/h
Fr. Apr. 25 10:00 pm
Wetter-Symbol
8° | 17°°C 0.2 mm 20% 7 mph 90 % 1023 mb 0 mm/h
Sa. Apr. 26 10:00 pm
Wetter-Symbol
11° | 18°°C 1 mm 100% 7 mph 98 % 1023 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
16° | 16°°C 0 mm 0% 8 mph 53 % 1017 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
16° | 16°°C 0 mm 0% 10 mph 49 % 1017 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
14° | 14°°C 0 mm 0% 11 mph 55 % 1016 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
10° | 10°°C 0 mm 0% 7 mph 76 % 1016 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
10° | 10°°C 0 mm 0% 7 mph 77 % 1014 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
9° | 9°°C 1 mm 100% 10 mph 94 % 1012 mb 0 mm/h
Tomorrow 7:00 am
Wetter-Symbol
8° | 8°°C 1 mm 100% 11 mph 93 % 1011 mb 0 mm/h
Tomorrow 10:00 am
Wetter-Symbol
8° | 8°°C 1 mm 100% 9 mph 93 % 1012 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€77,108.61
1.93%
Ethereum(ETH)
€1,418.67
0.33%
Fesseln(USDT)
€0.87
0.00%
XRP(XRP)
€1.83
-0.77%
Solana(SOL)
€122.12
0.82%
USDC(USDC)
€0.87
0.00%
Dogecoin(DOGE)
€0.143080
1.68%
Shiba Inu(SHIB)
€0.000011
0.04%
Pepe(PEPE)
€0.000007
4.07%
Nach oben scrollen