Advisory Database
  • Advisories
  • Dependency Scanning
  1. pypi
  2. ›
  3. sagemaker
  4. ›
  5. CVE-2024-34072

CVE-2024-34072: sagemaker-python-sdk vulnerable to Deserialization of Untrusted Data

May 3, 2024

sagemaker.base_deserializers.NumpyDeserializer module before v2.218.0 allows potentially unsafe deserialization when untrusted data is passed as pickled object arrays. This consequently may allow an unprivileged third party to cause remote code execution, denial of service, affecting both confidentiality and integrity.

Impacted versions: <2.218.0.

References

  • github.com/advisories/GHSA-wjvx-jhpj-r54r
  • github.com/aws/sagemaker-python-sdk
  • github.com/aws/sagemaker-python-sdk/commit/72e0c9712aec6fbb82fb40fda091dfc2a42c70a0
  • github.com/aws/sagemaker-python-sdk/pull/4557
  • github.com/aws/sagemaker-python-sdk/security/advisories/GHSA-wjvx-jhpj-r54r
  • nvd.nist.gov/vuln/detail/CVE-2024-34072

Code Behaviors & Features

Detect and mitigate CVE-2024-34072 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 2.218.0

Fixed versions

  • 2.218.0

Solution

Upgrade to version 2.218.0 or above.

Impact 7.8 HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Learn more about CVSS

Weakness

  • CWE-502: Deserialization of Untrusted Data

Source file

pypi/sagemaker/CVE-2024-34072.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Mon, 12 May 2025 12:14:19 +0000.