CVE-2023-2356: Relative Path Traversal in mlflow/mlflow
Published Apr 28, 2023
·Updated
Relative Path Traversal in GitHub repository mlflow/mlflow prior to 2.3.1.
Affected Software
2 affected componentsFixes available
pip/mlflow<2.3.1
2.3.1
Lfprojects Mlflow<2.3.1
Remediation
Event History
Apr 28, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Advisory Published
via GitHub·12:30 AM
Frequently Asked Questions
1
What is the vulnerability ID?
CVE-2023-2356
2
What is the severity of CVE-2023-2356?
The severity of CVE-2023-2356 is critical, with a severity value of 7.5.
3
What is the affected software?
The affected software is mlflow/mlflow prior to version 2.3.1.
4
How do I fix CVE-2023-2356?
To fix CVE-2023-2356, upgrade to version 2.3.1 or later of mlflow/mlflow.
5
What is the Common Weakness Enumeration (CWE) associated with CVE-2023-2356?
The Common Weakness Enumeration (CWE) associated with CVE-2023-2356 are CWE-22 and CWE-23.