CVE-2024-27134: Lfprojects MLflow
High severity, CVSS 7.0. EPSS: 0.1% chance of exploitation in the next 30 days.
Excessive directory permissions in MLflow leads to local privilege escalation when using spark_udf. This behavior can be exploited by a local attacker to gain elevated permissions by using a ToCToU attack. The issue is only relevant when the spark_udf() MLflow API is called.
Affected products
- Lfprojects MLflow: before 2.16.0 (fixed in 2.16.0)
Published 2024-11-25. Last modified 2026-06-17.