Skip to content
MLflowGHSA-wjq3-7jxx-whj9

mlflow Path Traversal vulnerability

Critical9.8CVE-2023-2780 · Published May 17, 2023 · updated Sep 24, 2024

mlflow prior to 2.3.0 is vulnerable to path traversal due to a bypass of the fix for CVE-2023-1177.

GitHub advisory

Affected versions

PackageAffectedFixed in
mlflow
PyPI
< 2.3.02.3.0
Details and references

More MLflow advisories

All MLflow
Advisory
MLflow Path Traversal vulnerability
Critical10.0Jul 19, 2023
mflow vulnerable to directory traversal
High7.5May 11, 2023
Remote file access vulnerability in `mlflow server` and `mlflow ui` CLIs
CriticalMay 1, 2023
Relative path traversal in mlflow
High10.0Apr 28, 2023
Remote file existence check vulnerability in `mlflow server` and `mlflow ui` CLIs
Medium3.3Mar 24, 2023
mlflow is vulnerable to remote file access in `mlflow server` and `mlflow ui` CLIs
Critical9.8Mar 24, 2023

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.