Skip to content
MLflowGHSA-x422-6qhv-p29g

Relative path traversal in mlflow

High10.0CVE-2023-2356 · Published Apr 28, 2023 · updated Feb 16, 2025

Relative Path Traversal in GitHub repository mlflow/mlflow prior to 2.3.1.

GitHub advisory

Affected versions

PackageAffectedFixed in
mlflow
PyPI
< 2.3.12.3.1
Details and references

More MLflow advisories

All MLflow
Advisory
MLflow Path Traversal vulnerability
Critical10.0Jul 19, 2023
mlflow Path Traversal vulnerability
Critical9.8May 17, 2023
mflow vulnerable to directory traversal
High7.5May 11, 2023
Remote file access vulnerability in `mlflow server` and `mlflow ui` CLIs
CriticalMay 1, 2023
Remote file existence check vulnerability in `mlflow server` and `mlflow ui` CLIs
Medium3.3Mar 24, 2023
mlflow is vulnerable to remote file access in `mlflow server` and `mlflow ui` CLIs
Critical9.8Mar 24, 2023

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.