diff --git a/mlflow.advisories.yaml b/mlflow.advisories.yaml index 4c8329048..5f167b63c 100644 --- a/mlflow.advisories.yaml +++ b/mlflow.advisories.yaml @@ -296,6 +296,24 @@ advisories: data: note: 'The latest versions have been recognized as affected. The upstream project has been alerted: https://github.com/mlflow/mlflow/issues/12256' + - id: CGA-hqfx-4c6f-wrjp + aliases: + - CVE-2024-56326 + - GHSA-q2x7-8rv6-6q7h + events: + - timestamp: 2024-12-24T08:30:45Z + type: detection + data: + type: scan/v1 + data: + subpackageName: mlflow + componentID: 814041681c0b86ed + componentName: jinja2 + componentVersion: 3.1.4 + componentType: python + componentLocation: /usr/share/mlflow/lib/python3.13/site-packages/jinja2-3.1.4.dist-info/METADATA, /usr/share/mlflow/lib/python3.13/site-packages/jinja2-3.1.4.dist-info/RECORD + scanner: grype + - id: CGA-jqq5-p5w5-hr5j aliases: - CVE-2024-37891