MLflowGHSA-x422-6qhv-p29g
Relative path traversal in mlflow
High10.0CVE-2023-2356 · Published Apr 28, 2023 · updated Feb 16, 2025
Relative Path Traversal in GitHub repository mlflow/mlflow prior to 2.3.1.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| mlflow PyPI | < 2.3.1 | 2.3.1 |
Details and references
- CVSS 3.0
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-23
- Also known as
- BIT-mlflow-2023-2356, CVE-2023-2356, PYSEC-2023-68
More MLflow advisories
All MLflow| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 192023 | MLflow Path Traversal vulnerability | Critical10.0 | 2.5.0 |
| May 172023 | mlflow Path Traversal vulnerability | Critical9.8 | 2.3.0 |
| May 112023 | mflow vulnerable to directory traversal | High7.5 | 2.0.0rc0 |
| May 12023 | Remote file access vulnerability in `mlflow server` and `mlflow ui` CLIs | Critical | 2.3.1 |
| Mar 242023 | Remote file existence check vulnerability in `mlflow server` and `mlflow ui` CLIs | Medium3.3 | 2.2.1 |
| Mar 242023 | mlflow is vulnerable to remote file access in `mlflow server` and `mlflow ui` CLIs | Critical9.8 | 2.2.1 |