VYPR

PyPI package

mlflow

pkg:pypi/mlflow

Vulnerabilities (69)

  • CVE-2023-6015HigNov 16, 2023
    affected < 2.8.1fixed 2.8.1

    MLflow allowed arbitrary files to be PUT onto the server.

  • CVE-2023-4033HigAug 1, 2023
    affected < 2.6.0fixed 2.6.0

    OS Command Injection in GitHub repository mlflow/mlflow prior to 2.6.0.

  • CVE-2023-3765CriJul 19, 2023
    affected < 2.5.0fixed 2.5.0

    Absolute Path Traversal in GitHub repository mlflow/mlflow prior to 2.5.0.

  • CVE-2023-2780CriMay 17, 2023
    affected < 2.3.0fixed 2.3.0

    Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.3.1.

  • CVE-2023-30172HigMay 11, 2023
    affected < 2.0.0rc0fixed 2.0.0rc0

    A directory traversal vulnerability in the /get-artifact API method of the mlflow platform up to v2.0.1 allows attackers to read arbitrary files on the server via the path parameter.

  • CVE-2023-2356HigApr 28, 2023
    affected < 2.3.1fixed 2.3.1

    Relative Path Traversal in GitHub repository mlflow/mlflow prior to 2.3.1.

  • CVE-2023-1177CriMar 24, 2023
    affected < 2.2.1fixed 2.2.1

    Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.2.1.

  • CVE-2023-1176LowMar 24, 2023
    affected < 2.2.1fixed 2.2.1

    Absolute Path Traversal in GitHub repository mlflow/mlflow prior to 2.2.2.

  • CVE-2022-0736HigFeb 23, 2022
    affected < 1.23.1fixed 1.23.1

    Insecure Temporary File in GitHub repository mlflow/mlflow prior to 1.23.1.

Page 4 of 4