VYPR
High severity7.5NVD Advisory· Published Mar 20, 2025· Updated Jun 17, 2026

CVE-2024-8859

CVE-2024-8859

Description

A path traversal vulnerability exists in mlflow/mlflow version 2.15.1. When users configure and use the dbfs service, concatenating the URL directly into the file protocol results in an arbitrary file read vulnerability. This issue occurs because only the path part of the URL is checked, while parts such as query and parameters are not handled. The vulnerability is triggered if the user has configured the dbfs service, and during usage, the service is mounted to a local directory.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
mlflowPyPI
< 2.17.0rc02.17.0rc0

Affected products

4
  • Mlflow/Mlflowcpe-rescue2 versions
    unspecified+ 1 more
    • (no CPE)range: unspecified
    • cpe:2.3:a:lfprojects:mlflow:2.15.1:*:*:*:*:*:*:*
  • ghsa-coords2 versions
    < 2.17.0rc0+ 1 more
    • (no CPE)range: < 2.17.0rc0
    • (no CPE)range: >= 2.15.1, < 2.16.0

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.