Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.9.2.
References
| Link | Resource |
|---|---|
| https://huntr.com/bounties/0acdd745-0167-4912-9d5c-02035fe5b314 | Exploit Third Party Advisory |
| https://github.com/mlflow/mlflow/commit/1da75dfcecd4d169e34809ade55748384e8af6c1 | Patch |
Configurations
Information
Published : 2023-12-15 01:15
Updated : 2023-12-21 15:10
NVD link : CVE-2023-6831
Mitre link : CVE-2023-6831
JSON object : View
Products Affected
lfprojects
- mlflow
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
