CVE-2024-34073 is an OS Command Injection vulnerability in the sagemaker-python-sdk, specifically within the capture_dependencies function when an inappropriate command is passed as the “requirements_path” parameter. This flaw affects versions prior to 2.214.3 of the library. Rated 7.8 HIGH (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H), this vulnerability allows for potential remote code execution, denial of service, and impacts confidentiality and integrity. The attack requires user interaction (UI:R) but has low attack complexity (AC:L). There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this CVE. Users are advised to upgrade to version 2.214.3 or avoid overriding the “requirements_path” parameter.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Aws | Sagemaker-Python-Sdk | < 2.214.3CNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.