'; } else{ echo ''; } echo '
|
|||
Release Date:2025/9/15
Rule Name:CVE-2024-2912,CVE-2025-27520:BentoML pickle Deserialization Vulnerability
Severity:critical
CVE ID:CVE-2024-2912 CVE-2025-27520
Descripiton:
|
BentoML is an open-source model service library developed by BentoML. Used to build high-performance and scalable artificial intelligence applications using Python. BentoML has a security vulnerability that stems from an insecure deserialization vulnerability that allows for remote code execution (RCE) by sending specially crafted POST requests. This rule supports to defend the A6: Vulnerabe and Outdated Components of OWASP Top 10 - 2021.
Other reference:None
Solution:
|
Update vendor patches.