Insecure Deserialization Leading to RCE in bentoml/bentoml
Published Apr 16, 2024
10.0
CRITICALCVSS 3.1
EPSS 1.51%
Description
An insecure deserialization vulnerability exists in the BentoML framework, allowing remote code execution (RCE) by sending a specially crafted POST request. By exploiting this vulnerability, attackers can execute arbitrary commands on the server hosting the BentoML application. The vulnerability is triggered when a serialized object, crafted to execute OS commands upon deserialization, is sent to any valid BentoML endpoint. This issue poses a significant security risk, enabling attackers to compromise the server and potentially gain unauthorized access or control.
Affected products
-
Affected
- ≥ 1.2.0, ≤ 1.2.4
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Bentoml | Bentoml/bentoml | unaffected | Affected
|
No data.
-
Affected
- ≥ 1.2.0, ≤ 1.2.4
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-1219 Advisory
- https://github.com/advisories/GHSA-hvj5-mvw9-93j3 Advisory
- https://github.com/bentoml/bentoml/commit/fd70379733c57c6368cc022ac1f841b7b426db7b
- https://huntr.com/bounties/349a1cce-6bb5-4345-82a5-bf7041b65a68
- https://nvd.nist.gov/vuln/detail/CVE-2024-2912
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub