Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
10
CVSSv3
CVE-2023-3765
Published: 19/07/2023 Updated: 28/07/2023
CVSS v3 Base Score: 10 | Impact Score: 6 | Exploitability Score: 3.9
VMScore: 0
Subscribe to Mlflow
Vulnerability Summary
Absolute Path Traversal in GitHub repository mlflow/mlflow before 2.5.0.
Vulnerability Trend
Vulnerable Product
Search on Vulmon
Subscribe to Product
lfprojects mlflow
Vendor Advisories
Check Point Security Alerts: MLflow Directory Traversal (CVE-2023-3765)
Check Point Reference: CPAI-2023-1449 Date Published: 15 Jan 2024 Severity: Critical ...
References
CWE-36
https://github.com/mlflow/mlflow/commit/6dde93758d42455cb90ef324407919ed67668b9b
https://huntr.dev/bounties/4be5fd63-8a0a-490d-9ee1-f33dc768ed76
https://nvd.nist.gov
https://advisories.checkpoint.com/defense/advisories/public/2024/cpai-2023-1449.html
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
remote code execution
CVE-2024-34909
CVE-2024-3317
SSTI
CVE-2024-3400
CVE-2024-30051
wireless
CVE-2024-4622
CVE-2024-4908
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started