CVE-2024-3099 is a medium-severity vulnerability affecting mlflow/mlflow version 2.11.1, allowing authenticated attackers to create multiple models with the same name by exploiting URL encoding. This can lead to Denial of Service (DoS) by preventing users from accessing the intended model, or data model poisoning if a user inadvertently utilizes a malicious model. The issue stems from inadequate validation of model names, enabling URL-encoded names to be treated as distinct. While the CVSS score is 5.4, indicating a medium risk with low attack complexity and potential for data integrity and availability impact, there is currently no evidence of active exploitation, public exploit code, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:lfprojects:mlflow:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.