Record summary

EIP currently links 1 Nuclei template to CVE-2023-6909.

Description

Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.9.2.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Apr 30, 2026 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

3
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied
CVE ListBefore 2.9.2affected
GitHub AdvisoryBefore 2.9.2 · Fixed in 2.9.2affected

Nuclei templates

1
ProjectDiscoveryHIGHMlflow <2.9.2 - Path TraversalCVSS 7.5

Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.9.2.

Impact

Successful exploitation could be lead to disclose of sensitive information such as SSH Keys or Internal configurations.

Remediation

To fix this vulnerability, it is important to update the mlflow package to the latest version 2.10.0.

WeaknessesCWE-29
AuthorsHyunsoo-ds
Template tagscvecve2023mlflowlfiintrusivelfprojectsvulnvkev
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:lfprojects:mlflow:*:*:*:*:*:*:*:*
Shodan: http.title:"mlflow"
FOFA: title="mlflow"
FOFA: app="mlflow"
Google: intitle:"mlflow"

Source: ProjectDiscovery

References

5