MLflowGHSA-hq88-wg7q-gp4g
mlflow vulnerable to Path Traversal
Critical9.3CVE-2024-3573 · Published Apr 16, 2024 · updated Apr 8, 2025
mlflow/mlflow is vulnerable to Local File Inclusion (LFI) due to improper parsing of URIs, allowing attackers to bypass checks and read arbitrary files on the system. The issue arises from the 'is_local_uri' function's failure to properly handle URIs with empty or 'file' schemes, leading to the misclassification of URIs as non-local. Attackers can exploit this by crafting malicious model versions with specially crafted 'source' parameters, enabling the reading of sensitive files within at least two directory levels from the server's root.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| mlflow PyPI | < 2.10.0 | 2.10.0 |
Details and references
- CVSS 3.0
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-29
- Also known as
- BIT-mlflow-2024-3573, CVE-2024-3573, PYSEC-2024-243
More MLflow advisories
All MLflow| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| May 162024 | MLflow has a Local File Read/Path Traversal bypass | High7.5 | 2.12.1 |
| Apr 162024 | mlflow vulnerable to Path Traversal | High8.1 | No fix yet |
| Apr 162024 | mlflow vulnerable to Path Traversal | High7.5 | No fix yet |
| Apr 162024 | mlflow vulnerable to Path Traversal | High7.5 | 2.12.1 |
| Apr 162024 | mlflow vulnerable to Path Traversal | High7.5 | No fix yet |
| Apr 162024 | mlflow Path Traversal vulnerability | High7.5 | 2.12.1 |