VYPR
Critical severity9.3NVD Advisory· Published Apr 16, 2024· Updated Jun 17, 2026

CVE-2024-3573

CVE-2024-3573

Description

mlflow/mlflow is vulnerable to Local File Inclusion (LFI) due to improper parsing of URIs, allowing attackers to bypass checks and read arbitrary files on the system. The issue arises from the 'is_local_uri' function's failure to properly handle URIs with empty or 'file' schemes, leading to the misclassification of URIs as non-local. Attackers can exploit this by crafting malicious model versions with specially crafted 'source' parameters, enabling the reading of sensitive files within at least two directory levels from the server's root.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
mlflowPyPI
< 2.10.02.10.0

Affected products

4
  • ghsa-coords2 versions
    < 2.10.0+ 1 more
    • (no CPE)range: < 2.10.0
    • (no CPE)range: < 2.10.0
  • Mlflow/Mlflow2 versions
    cpe:2.3:a:lfprojects:mlflow:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:lfprojects:mlflow:*:*:*:*:*:*:*:*range: <2.10.0
    • (no CPE)range: unspecified

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.