Lfprojects Mlflow < 2.2.1 - Path Traversal
Title source: ruleDescription
Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.2.1.
Exploits (8)
github
WORKING POC
by wnaspy · shellpoc
https://github.com/wnaspy/CVE-POC-WEAPON/tree/main/CVE-2023-1177.py
nomisec
WORKING POC
by paultheal1en · infoleak
https://github.com/paultheal1en/CVE-2023-1177-PoC-reproduce
Nuclei Templates (1)
Mlflow <2.2.1 - Local File Inclusion
CRITICALVERIFIEDby iamnoooob,pdresearch
Shodan:
http.title:"mlflow"
FOFA:
title="mlflow" || app="mlflow"
Scores
CVSS v3
9.3
EPSS
0.9331
EPSS Percentile
99.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
Lab Environment
COMMUNITY
Community Lab
+4 more repos
Details
VulnCheck KEV
2023-12-01
CWE
CWE-29
CWE-22
Status
published
Products (2)
lfprojects/mlflow
< 2.2.1
pypi/mlflow
0 - 2.2.1PyPI
Published
Mar 24, 2023
Tracked Since
Feb 18, 2026