Launch Week Day 1: Announcing Security Design Review
HIGH 7.5 PyPI

mlflow vulnerable to Path Traversal

GHSA-m49c-5c52-6696 · BIT-mlflow-2024-1594 · CVE-2024-1594

Published · Modified

Description

A path traversal vulnerability exists in the mlflow/mlflow repository, specifically within the handling of the artifact_location parameter when creating an experiment. Attackers can exploit this vulnerability by using a fragment component # in the artifact location URI to read arbitrary files on the server in the context of the server's process. This issue is similar to CVE-2023-6909 but utilizes a different component of the URI to achieve the same effect.

Ready to move

Start Securing

Free, no credit card | First findings in minutes