VYPR
High severity7.5NVD Advisory· Published Apr 16, 2024· Updated Jun 17, 2026

CVE-2024-1594

CVE-2024-1594

Description

A path traversal vulnerability exists in the mlflow/mlflow repository, specifically within the handling of the artifact_location parameter when creating an experiment. Attackers can exploit this vulnerability by using a fragment component # in the artifact location URI to read arbitrary files on the server in the context of the server's process. This issue is similar to CVE-2023-6909 but utilizes a different component of the URI to achieve the same effect.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
mlflowPyPI
<= 2.9.2

Affected products

4
  • ghsa-coords2 versions
    <= 2.9.2+ 1 more
    • (no CPE)range: <= 2.9.2
    • (no CPE)range: < 2.11.3
  • Mlflow/Mlflow2 versions
    cpe:2.3:a:lfprojects:mlflow:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:lfprojects:mlflow:*:*:*:*:*:*:*:*range: <2.11.3
    • (no CPE)range: unspecified

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.