PyPI package
mlflow
pkg:pypi/mlflow
Vulnerabilities (69)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2023-6015 | Hig | 7.5 | < 2.8.1 | 2.8.1 | Nov 16, 2023 | MLflow allowed arbitrary files to be PUT onto the server. | |
| CVE-2023-4033 | Hig | 7.8 | < 2.6.0 | 2.6.0 | Aug 1, 2023 | OS Command Injection in GitHub repository mlflow/mlflow prior to 2.6.0. | |
| CVE-2023-3765 | Cri | 10.0 | < 2.5.0 | 2.5.0 | Jul 19, 2023 | Absolute Path Traversal in GitHub repository mlflow/mlflow prior to 2.5.0. | |
| CVE-2023-2780 | Cri | 9.8 | < 2.3.0 | 2.3.0 | May 17, 2023 | Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.3.1. | |
| CVE-2023-30172 | Hig | 7.5 | < 2.0.0rc0 | 2.0.0rc0 | May 11, 2023 | A directory traversal vulnerability in the /get-artifact API method of the mlflow platform up to v2.0.1 allows attackers to read arbitrary files on the server via the path parameter. | |
| CVE-2023-2356 | Hig | 7.5 | < 2.3.1 | 2.3.1 | Apr 28, 2023 | Relative Path Traversal in GitHub repository mlflow/mlflow prior to 2.3.1. | |
| CVE-2023-1177 | Cri | 9.3 | < 2.2.1 | 2.2.1 | Mar 24, 2023 | Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.2.1. | |
| CVE-2023-1176 | Low | 3.3 | < 2.2.1 | 2.2.1 | Mar 24, 2023 | Absolute Path Traversal in GitHub repository mlflow/mlflow prior to 2.2.2. | |
| CVE-2022-0736 | Hig | 7.5 | < 1.23.1 | 1.23.1 | Feb 23, 2022 | Insecure Temporary File in GitHub repository mlflow/mlflow prior to 1.23.1. |
- affected < 2.8.1fixed 2.8.1
MLflow allowed arbitrary files to be PUT onto the server.
- affected < 2.6.0fixed 2.6.0
OS Command Injection in GitHub repository mlflow/mlflow prior to 2.6.0.
- affected < 2.5.0fixed 2.5.0
Absolute Path Traversal in GitHub repository mlflow/mlflow prior to 2.5.0.
- affected < 2.3.0fixed 2.3.0
Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.3.1.
- affected < 2.0.0rc0fixed 2.0.0rc0
A directory traversal vulnerability in the /get-artifact API method of the mlflow platform up to v2.0.1 allows attackers to read arbitrary files on the server via the path parameter.
- affected < 2.3.1fixed 2.3.1
Relative Path Traversal in GitHub repository mlflow/mlflow prior to 2.3.1.
- affected < 2.2.1fixed 2.2.1
Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.2.1.
- affected < 2.2.1fixed 2.2.1
Absolute Path Traversal in GitHub repository mlflow/mlflow prior to 2.2.2.
- affected < 1.23.1fixed 1.23.1
Insecure Temporary File in GitHub repository mlflow/mlflow prior to 1.23.1.
Page 4 of 4