Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
lfprojects mlflow vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2023-43472
An issue in MLFlow versions 2.8.1 and before allows a remote malicious user to obtain sensitive information via a crafted request to REST API.
Lfprojects Mlflow
NA
CVE-2023-6014
An attacker is able to arbitrarily create an account in MLflow bypassing any authentication requirment.
Lfprojects Mlflow
NA
CVE-2023-6015
MLflow allowed arbitrary files to be PUT onto the server.
Lfprojects Mlflow
1 Github repository
NA
CVE-2023-6018
An attacker can overwrite any file on the server hosting MLflow without any authentication.
Lfprojects Mlflow -
NA
CVE-2023-4033
OS Command Injection in GitHub repository mlflow/mlflow before 2.6.0.
Lfprojects Mlflow
NA
CVE-2023-3765
Absolute Path Traversal in GitHub repository mlflow/mlflow before 2.5.0.
Lfprojects Mlflow
NA
CVE-2023-2780
Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow before 2.3.1.
Lfprojects Mlflow
NA
CVE-2023-30172
A directory traversal vulnerability in the /get-artifact API method of the mlflow platform up to v2.0.1 allows malicious users to read arbitrary files on the server via the path parameter.
Lfprojects Mlflow
NA
CVE-2023-2356
Relative Path Traversal in GitHub repository mlflow/mlflow before 2.3.1.
Lfprojects Mlflow
NA
CVE-2023-1177
Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow before 2.2.1.
Lfprojects Mlflow
3 Github repositories
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2020-4463
CVE-2024-29895
inject
CVE-2023-52689
CVE-2024-5049
CVE-2024-5051
privilege escalation
physical
CVE-2023-52676
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
NEXT »