github.com
https://github.com/mlflow/mlflow CVE-2023-6831
HIGHNuclei
Path Traversal: '\..\filename' in mlflow/mlflow
Record summary
CVE-2023-6831 has a selected CVSS score of 8.1 (high); EIP currently links 1 Nuclei template.
Description
Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.9.2.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
mlflow/mlflowBrowse mlflow / mlflow/mlflow | CVE List | Before 2.9.2 | affected |
mlflowBrowse PyPI / mlflow | GitHub Advisory | Before 2.9.2 · Fixed in 2.9.2 | affected |
Nuclei templates
1ProjectDiscoveryHIGHmlflow - Path TraversalCVSS 8.1
Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.9.2.
Impact
Authenticated attackers can exploit path traversal vulnerabilities to delete arbitrary files on mlflow servers through crafted API requests.
Remediation
Upgrade Mlflow to version 2.9.2 or later to mitigate the vulnerability.
WeaknessesCWE-22CWE-29
AuthorsbyObin
Template tagscvecve2023mlflowpathtraversallfprojectsintrusivevuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
CPE: cpe:2.3:a:lfprojects:mlflow:*:*:*:*:*:*:*:*
Shodan: http.title:"mlflow"
FOFA: title="mlflow"
FOFA: app="mlflow"
Google: intitle:"mlflow"
https://nvd.nist.gov/vuln/detail/CVE-2023-6831 https://github.com/mlflow/mlflow/commit/1da75dfcecd4d169e34809ade55748384e8af6c1 https://huntr.com/bounties/0acdd745-0167-4912-9d5c-02035fe5b314
Source: ProjectDiscovery
References
5github.com
https://github.com/mlflow/mlflow/commit/1da75dfcecd4d169e34809ade55748384e8af6c1 github.com
https://github.com/pypa/advisory-database/tree/main/vulns/mlflow/PYSEC-2023-253.yaml huntr.com
https://huntr.com/bounties/0acdd745-0167-4912-9d5c-02035fe5b314 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-6831