github.com
https://github.com/mlflow/mlflow CVE-2023-6018
CRITICALNuclei
MLflow Arbitrary File Write
Record summary
CVE-2023-6018 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
An attacker can overwrite any file on the server hosting MLflow without any authentication.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
mlflow/mlflowBrowse mlflow / mlflow/mlflow | CVE List | Through latest | affected |
mlflowBrowse PyPI / mlflow | GitHub Advisory | Before 2.9.2 · Fixed in 2.9.2 | affected |
Nuclei templates
1ProjectDiscoveryCRITICALMlflow - Arbitrary File WriteCVSS 9.8
An attacker can overwrite any file on the server hosting MLflow without any authentication.
Impact
Unauthenticated attackers can overwrite any file on the server hosting MLflow, potentially compromising system integrity and enabling remote code execution.
Remediation
Secure the MLflow instance by implementing authentication and access controls, and update to the latest patched version.
WeaknessesCWE-78
Authorsbyt3bl33d3r
Template tagscvecve2023mlflowossrceintrusivelfprojectsvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:lfprojects:mlflow:-:*:*:*:*:*:*:*
Shodan: http.title:"mlflow"
FOFA: title="mlflow"
FOFA: app="mlflow"
Google: intitle:"mlflow"
https://huntr.com/bounties/7cf918b5-43f4-48c0-a371-4d963ce69b30/ https://nvd.nist.gov/vuln/detail/CVE-2023-6018
Source: ProjectDiscovery
References
4github.com
https://github.com/mlflow/mlflow/commit/55c72d02380e8db8118595a4fdae7879cb7ac5bd huntr.com
https://huntr.com/bounties/7cf918b5-43f4-48c0-a371-4d963ce69b30 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-6018