CVE-2023-1176
Published on: Not Yet Published
Last Modified on: 03/28/2023 02:44:00 PM UTC
CVE-2023-1176 - advisory for ae92f814-6a08-435c-8445-eec0ef4f1085
Source: Mitre Source: NIST CVE.ORG Print: PDF
Certain versions of Mlflow from Lfprojects contain the following vulnerability:
Absolute Path Traversal in GitHub repository mlflow/mlflow prior to 2.2.2.
- CVE-2023-1176 has been assigned by
sec[email protected] to track the vulnerability - currently rated as LOW severity.
- Affected Vendor/Software:
mlflow - mlflow/mlflow version < 2.2.2
CVSS3 Score: 3.3 - LOW
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
LOCAL | LOW | LOW | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | LOW | NONE | NONE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Prevent registered model name from containing path separator (#7892) · mlflow/mlflow@63ef72a · GitHub | github.com text/html |
![]() |
huntr: Page not found | huntr.dev text/html |
![]() |
There are currently no QIDs associated with this CVE
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Lfprojects | Mlflow | All | All | All | All |
- cpe:2.3:a:lfprojects:mlflow:*:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
mlflow/mlflow disclosed a bug reported by danmcinerney (CVE-2023-1176) - Patch: github.com/mlflow/mlflow/…… twitter.com/i/web/status/1… | 2023-03-24 15:01:40 |
![]() |
CVE-2023-1176 : Absolute Path Traversal in GitHub repository mlflow/mlflow prior to 2.2.1.... cve.report/CVE-2023-1176 | 2023-03-24 15:04:46 |
![]() |
CVE-2023-1176 | 2023-03-24 16:38:16 |