Vulnerabilities (CVE)

Filtered by vendor Lfprojects Subscribe
Filtered by product Mlflow
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-6940 1 Lfprojects 1 Mlflow 2023-12-29 N/A 8.8 HIGH
with only one user interaction(download a malicious config), attackers can gain full command execution on the victim system.
CVE-2023-6977 1 Lfprojects 1 Mlflow 2023-12-29 N/A 7.5 HIGH
This vulnerability enables malicious users to read sensitive files on the server.
CVE-2023-6976 1 Lfprojects 1 Mlflow 2023-12-29 N/A 8.8 HIGH
This vulnerability is capable of writing arbitrary files into arbitrary locations on the remote filesystem in the context of the server process.
CVE-2023-6831 1 Lfprojects 1 Mlflow 2023-12-21 N/A 8.1 HIGH
Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.9.2.
CVE-2023-6909 1 Lfprojects 1 Mlflow 2023-12-20 N/A 7.5 HIGH
Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.9.2.
CVE-2023-6753 2 Lfprojects, Microsoft 2 Mlflow, Windows 2023-12-15 N/A 8.8 HIGH
Path Traversal in GitHub repository mlflow/mlflow prior to 2.9.2.
CVE-2023-6709 1 Lfprojects 1 Mlflow 2023-12-13 N/A 8.8 HIGH
Improper Neutralization of Special Elements Used in a Template Engine in GitHub repository mlflow/mlflow prior to 2.9.2.
CVE-2023-43472 1 Lfprojects 1 Mlflow 2023-12-11 N/A 7.5 HIGH
An issue in MLFlow versions 2.8.1 and before allows a remote attacker to obtain sensitive information via a crafted request to REST API.
CVE-2023-6015 1 Lfprojects 1 Mlflow 2023-11-29 N/A 7.5 HIGH
MLflow allowed arbitrary files to be PUT onto the server.
CVE-2023-4033 1 Lfprojects 1 Mlflow 2023-08-04 N/A 7.8 HIGH
OS Command Injection in GitHub repository mlflow/mlflow prior to 2.6.0.