Record summary

CVE-2023-6831 has a selected CVSS score of 8.1 (high); EIP currently links 1 Nuclei template.

Description

Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.9.2.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

2
ProductSourceVersion rangeStatus
CVE ListBefore 2.9.2affected
GitHub AdvisoryBefore 2.9.2 · Fixed in 2.9.2affected

Nuclei templates

1
ProjectDiscoveryHIGHmlflow - Path TraversalCVSS 8.1

Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.9.2.

Impact

Authenticated attackers can exploit path traversal vulnerabilities to delete arbitrary files on mlflow servers through crafted API requests.

Remediation

Upgrade Mlflow to version 2.9.2 or later to mitigate the vulnerability.

WeaknessesCWE-22CWE-29
AuthorsbyObin
Template tagscvecve2023mlflowpathtraversallfprojectsintrusivevuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
CPE: cpe:2.3:a:lfprojects:mlflow:*:*:*:*:*:*:*:*
Shodan: http.title:"mlflow"
FOFA: title="mlflow"
FOFA: app="mlflow"
Google: intitle:"mlflow"

Source: ProjectDiscovery

References

5