Vulnerabilities (CVE)

Filtered by CWE-29
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-6977 1 Lfprojects 1 Mlflow 2023-12-29 N/A 7.5 HIGH
This vulnerability enables malicious users to read sensitive files on the server.
CVE-2023-6975 1 Lfprojects 1 Mlflow 2023-12-29 N/A 9.8 CRITICAL
A malicious user could use this issue to get command execution on the vulnerable machine and get access to data & models information.
CVE-2023-6909 1 Lfprojects 1 Mlflow 2023-12-20 N/A 7.5 HIGH
Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.9.2.