MLflowGHSA-wjq3-7jxx-whj9
mlflow Path Traversal vulnerability
Critical9.8CVE-2023-2780 · Published May 17, 2023 · updated Sep 24, 2024
mlflow prior to 2.3.0 is vulnerable to path traversal due to a bypass of the fix for CVE-2023-1177.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| mlflow PyPI | < 2.3.0 | 2.3.0 |
Details and references
- CVSS 3.0
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-29
- Also known as
- BIT-mlflow-2023-2780, CVE-2023-2780, PYSEC-2023-69
More MLflow advisories
All MLflow| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 192023 | MLflow Path Traversal vulnerability | Critical10.0 | 2.5.0 |
| May 112023 | mflow vulnerable to directory traversal | High7.5 | 2.0.0rc0 |
| May 12023 | Remote file access vulnerability in `mlflow server` and `mlflow ui` CLIs | Critical | 2.3.1 |
| Apr 282023 | Relative path traversal in mlflow | High10.0 | 2.3.1 |
| Mar 242023 | Remote file existence check vulnerability in `mlflow server` and `mlflow ui` CLIs | Medium3.3 | 2.2.1 |
| Mar 242023 | mlflow is vulnerable to remote file access in `mlflow server` and `mlflow ui` CLIs | Critical9.8 | 2.2.1 |