CVE-2023-1177

CRITICAL EXPLOITED NUCLEI LAB

Lfprojects Mlflow < 2.2.1 - Path Traversal

Title source: rule

Description

Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.2.1.

Exploits (8)

github WORKING POC
by wnaspy · shellpoc
https://github.com/wnaspy/CVE-POC-WEAPON/tree/main/CVE-2023-1177.py
nomisec WORKING POC
by paultheal1en · infoleak
https://github.com/paultheal1en/CVE-2023-1177-PoC-reproduce
nomisec NO CODE
by charlesgargasson · infoleak
https://github.com/charlesgargasson/CVE-2023-1177
nomisec WRITEUP
by saimahmed · poc
https://github.com/saimahmed/MLflow-Vuln
nomisec WORKING POC
by hh-hunter · poc
https://github.com/hh-hunter/ml-CVE-2023-1177
nomisec WORKING POC
by SpycioKon · poc
https://github.com/SpycioKon/CVE-2023-1177-rebuild
nomisec WORKING POC
by alphandbelt1 · poc
https://github.com/alphandbelt1/CVE-2023-1177-MLFlow

Nuclei Templates (1)

Mlflow <2.2.1 - Local File Inclusion
CRITICALVERIFIEDby iamnoooob,pdresearch
Shodan: http.title:"mlflow"
FOFA: title="mlflow" || app="mlflow"

Scores

CVSS v3 9.3
EPSS 0.9331
EPSS Percentile 99.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N

Lab Environment

COMMUNITY
Community Lab
docker pull ghcr.io/mlflow/mlflow:v2.2.0
docker pull ghcr.io/mlflow/mlflow:v2.0.0
docker pull ghcr.io/mlflow/mlflow-devcontainer
docker pull minio/minio
docker pull minio/mc
+4 more repos

Details

VulnCheck KEV 2023-12-01
CWE
CWE-29 CWE-22
Status published
Products (2)
lfprojects/mlflow < 2.2.1
pypi/mlflow 0 - 2.2.1PyPI
Published Mar 24, 2023
Tracked Since Feb 18, 2026