MLflowGHSA-wc6j-5g83-xfm6
mflow vulnerable to directory traversal
High7.5CVE-2023-30172 · Published May 11, 2023 · updated Feb 16, 2024
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| mlflow PyPI | < 2.0.0rc0 | 2.0.0rc0 |
Details and references
A directory traversal vulnerability in the /get-artifact API method of the mlflow platform prior to v2.0.0 allows attackers to read arbitrary files on the server via the path parameter.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-22
- Also known as
- BIT-mlflow-2023-30172, CVE-2023-30172, PYSEC-2023-70
- nvd.nist.gov/vuln/detail/CVE-2023-30172
- github.com/mlflow/mlflow/issues/7166
- github.com/mlflow/mlflow/issues/7166#issuecomment-1541543234
- github.com/mlflow/mlflow/pull/7170
- github.com/mlflow/mlflow/commit/ac4b697bb0bb8a331944dca63f4235b4bf602ab8
- github.com/mlflow/mlflow
- github.com/mlflow/mlflow/commits/v2.0.0?after=00c3b0a350a28c25b16fbb7feddb8147a919ce18+69&branch=v2.0.0&qualified_name=refs%2Ftags%2Fv2.0.0
- github.com/pypa/advisory-database/tree/main/vulns/mlflow/PYSEC-2023-70.yaml
More MLflow advisories
All MLflow| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| May 172023 | mlflow Path Traversal vulnerability CVE-2023-2780Critical9.8fixed in 2.3.0 | Critical9.8 | 2.3.0 |
| May 12023 | Remote file access vulnerability in `mlflow server` and `mlflow ui` CLIs GHSA-83fm-w79m-64r5Criticalfixed in 2.3.1 | Critical | 2.3.1 |
| Apr 282023 | Relative path traversal in mlflow CVE-2023-2356High10.0fixed in 2.3.1 | High10.0 | 2.3.1 |
| Mar 242023 | Remote file existence check vulnerability in `mlflow server` and `mlflow ui` CLIs CVE-2023-1176Medium3.3fixed in 2.2.1 | Medium3.3 | 2.2.1 |
| Mar 242023 | mlflow is vulnerable to remote file access in `mlflow server` and `mlflow ui` CLIs CVE-2023-1177Critical9.8fixed in 2.2.1 | Critical9.8 | 2.2.1 |
| Jul 192023 | MLflow Path Traversal vulnerability CVE-2023-3765Critical10.0fixed in 2.5.0 | Critical10.0 | 2.5.0 |