VYPR
High severity8.1NVD Advisory· Published Apr 16, 2024· Updated Jun 17, 2026

CVE-2024-1560

CVE-2024-1560

Description

A path traversal vulnerability exists in the mlflow/mlflow repository, specifically within the artifact deletion functionality. Attackers can bypass path validation by exploiting the double decoding process in the _delete_artifact_mlflow_artifacts handler and local_file_uri_to_path function, allowing for the deletion of arbitrary directories on the server's filesystem. This vulnerability is due to an extra unquote operation in the delete_artifacts function of local_artifact_repo.py, which fails to properly sanitize user-supplied paths. The issue is present up to version 2.9.2, despite attempts to fix a similar issue in CVE-2023-6831.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
mlflowPyPI
<= 2.9.2

Affected products

4
  • ghsa-coords2 versions
    <= 2.9.2+ 1 more
    • (no CPE)range: <= 2.9.2
    • (no CPE)range: < 2.12.2
  • Mlflow/Mlflow2 versions
    cpe:2.3:a:lfprojects:mlflow:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:lfprojects:mlflow:*:*:*:*:*:*:*:*range: <=2.9.2
    • (no CPE)range: unspecified

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.