CVE-2024-34072: sagemaker-python-sdk vulnerable to Deserialization of Untrusted Data
sagemaker.base_deserializers.NumpyDeserializer module before v2.218.0 allows potentially unsafe deserialization when untrusted data is passed as pickled object arrays. This consequently may allow an unprivileged third party to cause remote code execution, denial of service, affecting both confidentiality and integrity.
Impacted versions: <2.218.0.
References
- github.com/advisories/GHSA-wjvx-jhpj-r54r
- github.com/aws/sagemaker-python-sdk
- github.com/aws/sagemaker-python-sdk/commit/72e0c9712aec6fbb82fb40fda091dfc2a42c70a0
- github.com/aws/sagemaker-python-sdk/pull/4557
- github.com/aws/sagemaker-python-sdk/security/advisories/GHSA-wjvx-jhpj-r54r
- nvd.nist.gov/vuln/detail/CVE-2024-34072
Detect and mitigate CVE-2024-34072 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →