Critical severity9.8NVD Advisory· Published Nov 16, 2023· Updated Jun 17, 2026
CVE-2023-6018
CVE-2023-6018
Description
An attacker can overwrite any file on the server hosting MLflow without any authentication.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
mlflowPyPI | < 2.9.2 | 2.9.2 |
Affected products
4Patches
Vulnerability mechanics
References
4- huntr.com/bounties/7cf918b5-43f4-48c0-a371-4d963ce69b30nvdExploitTechnical DescriptionThird Party AdvisoryWEB
- github.com/advisories/GHSA-5p3h-7fwh-92rcghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-6018ghsaADVISORY
- github.com/mlflow/mlflow/commit/55c72d02380e8db8118595a4fdae7879cb7ac5bdghsaWEB
News mentions
0No linked articles in our index yet.