Skip to content
MLflowGHSA-wc6j-5g83-xfm6

mflow vulnerable to directory traversal

High7.5CVE-2023-30172 · Published May 11, 2023 · updated Feb 16, 2024

GitHub advisory

Affected versions

PackageAffectedFixed in
mlflow
PyPI
< 2.0.0rc02.0.0rc0
Details and references

A directory traversal vulnerability in the /get-artifact API method of the mlflow platform prior to v2.0.0 allows attackers to read arbitrary files on the server via the path parameter.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-22
Also known as
BIT-mlflow-2023-30172, CVE-2023-30172, PYSEC-2023-70

More MLflow advisories

All MLflow
DateAdvisory
May 172023mlflow Path Traversal vulnerability
CVE-2023-2780Critical9.8fixed in 2.3.0
May 12023Remote file access vulnerability in `mlflow server` and `mlflow ui` CLIs
GHSA-83fm-w79m-64r5Criticalfixed in 2.3.1
Apr 282023Relative path traversal in mlflow
CVE-2023-2356High10.0fixed in 2.3.1
Mar 242023Remote file existence check vulnerability in `mlflow server` and `mlflow ui` CLIs
CVE-2023-1176Medium3.3fixed in 2.2.1
Mar 242023mlflow is vulnerable to remote file access in `mlflow server` and `mlflow ui` CLIs
CVE-2023-1177Critical9.8fixed in 2.2.1
Jul 192023MLflow Path Traversal vulnerability
CVE-2023-3765Critical10.0fixed in 2.5.0

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.