High severity7.5NVD Advisory· Published Apr 16, 2024· Updated Jun 17, 2026
CVE-2024-1594
CVE-2024-1594
Description
A path traversal vulnerability exists in the mlflow/mlflow repository, specifically within the handling of the artifact_location parameter when creating an experiment. Attackers can exploit this vulnerability by using a fragment component # in the artifact location URI to read arbitrary files on the server in the context of the server's process. This issue is similar to CVE-2023-6909 but utilizes a different component of the URI to achieve the same effect.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
mlflowPyPI | <= 2.9.2 | — |
Affected products
4- ghsa-coords2 versions
<= 2.9.2+ 1 more
- (no CPE)range: <= 2.9.2
- (no CPE)range: < 2.11.3
Patches
Vulnerability mechanics
References
4- huntr.com/bounties/424b6f6b-e778-4a2b-b860-39730d396f3envdExploitIssue TrackingThird Party AdvisoryWEB
- github.com/advisories/GHSA-m49c-5c52-6696ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-1594ghsaADVISORY
- github.com/mlflow/mlflow/blob/b929a3e727dc48a1eb19b7e954b7897ac09ad3ec/mlflow/utils/uri.pyghsaWEB
News mentions
0No linked articles in our index yet.