MLflowGHSA-ffw3-6378-cqgp
mlflow vulnerable to OS Command Injection
High8.8CVE-2023-4033 · Published Aug 1, 2023 · updated Nov 22, 2024
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| mlflow PyPI | < 2.6.0 | 2.6.0 |
Details and references
OS Command Injection in GitHub repository mlflow/mlflow prior to 2.6.0.
- CVSS 3.0
- CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-78
- Also known as
- BIT-mlflow-2023-4033, CVE-2023-4033, PYSEC-2023-280
More MLflow advisories
All MLflow| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 192023 | MLflow Path Traversal vulnerability CVE-2023-3765Critical10.0fixed in 2.5.0 | Critical10.0 | 2.5.0 |
| May 172023 | mlflow Path Traversal vulnerability CVE-2023-2780Critical9.8fixed in 2.3.0 | Critical9.8 | 2.3.0 |
| May 112023 | mflow vulnerable to directory traversal CVE-2023-30172High7.5fixed in 2.0.0rc0 | High7.5 | 2.0.0rc0 |
| May 12023 | Remote file access vulnerability in `mlflow server` and `mlflow ui` CLIs GHSA-83fm-w79m-64r5Criticalfixed in 2.3.1 | Critical | 2.3.1 |
| Apr 282023 | Relative path traversal in mlflow CVE-2023-2356High10.0fixed in 2.3.1 | High10.0 | 2.3.1 |
| Nov 162023 | Remote Code Execution due to Full Controled File Write in mlflow CVE-2023-6018Critical10.0fixed in 2.9.2 | Critical10.0 | 2.9.2 |