CVE-2024-2912 is a critical insecure deserialization vulnerability in the BentoML framework, allowing remote code execution (RCE) without requiring authentication. Attackers can exploit this by sending a specially crafted POST request containing a malicious serialized object to any valid BentoML endpoint. This vulnerability carries a CVSS score of 10.0 (Critical), indicating a severe risk of complete system compromise, including unauthorized access, data manipulation, and service disruption. While no active exploitation or public exploit code has been identified yet, its high severity and ease of exploitation warrant immediate attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Bentoml | Bentoml/Bentoml | >= 1.2.0, <= 1.2.4CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.