Skip to content
MLflowGHSA-ffw3-6378-cqgp

mlflow vulnerable to OS Command Injection

High8.8CVE-2023-4033 · Published Aug 1, 2023 · updated Nov 22, 2024

GitHub advisory

Affected versions

PackageAffectedFixed in
mlflow
PyPI
< 2.6.02.6.0
Details and references

OS Command Injection in GitHub repository mlflow/mlflow prior to 2.6.0.

CVSS 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-78
Also known as
BIT-mlflow-2023-4033, CVE-2023-4033, PYSEC-2023-280

More MLflow advisories

All MLflow
DateAdvisory
Jul 192023MLflow Path Traversal vulnerability
CVE-2023-3765Critical10.0fixed in 2.5.0
May 172023mlflow Path Traversal vulnerability
CVE-2023-2780Critical9.8fixed in 2.3.0
May 112023mflow vulnerable to directory traversal
CVE-2023-30172High7.5fixed in 2.0.0rc0
May 12023Remote file access vulnerability in `mlflow server` and `mlflow ui` CLIs
GHSA-83fm-w79m-64r5Criticalfixed in 2.3.1
Apr 282023Relative path traversal in mlflow
CVE-2023-2356High10.0fixed in 2.3.1
Nov 162023Remote Code Execution due to Full Controled File Write in mlflow
CVE-2023-6018Critical10.0fixed in 2.9.2

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.