Vulnerabilities
Vulnerable Software
Lfprojects:  >> Mlflow  >> 2.9.1  Security Vulnerabilities
This vulnerability is capable of writing arbitrary files into arbitrary locations on the remote filesystem in the context of the server process.
CVSS Score
8.8
EPSS Score
0.001
Published
2023-12-20
This vulnerability enables malicious users to read sensitive files on the server.
CVSS Score
10.0
EPSS Score
0.83
Published
2023-12-20
with only one user interaction(download a malicious config), attackers can gain full command execution on the victim system.
CVSS Score
9.0
EPSS Score
0.002
Published
2023-12-19
Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.9.2.
CVSS Score
7.5
EPSS Score
0.857
Published
2023-12-18
Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.9.2.
CVSS Score
8.1
EPSS Score
0.74
Published
2023-12-15
Path Traversal in GitHub repository mlflow/mlflow prior to 2.9.2.
CVSS Score
9.6
EPSS Score
0.024
Published
2023-12-13
Improper Neutralization of Special Elements Used in a Template Engine in GitHub repository mlflow/mlflow prior to 2.9.2.
CVSS Score
10.0
EPSS Score
0.003
Published
2023-12-12
An attacker is able to arbitrarily create an account in MLflow bypassing any authentication requirment.
CVSS Score
9.1
EPSS Score
0.009
Published
2023-11-16


Contact Us

Shodan ® - All rights reserved