CVE-2023-2780: Path Traversal: '\..\filename' in mlflow/mlflow
Published May 17, 2023
·Updated
mlflow prior to 2.3.0 is vulnerable to path traversal due to a bypass of the fix for CVE-2023-1177.
Other sources
Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.3.1.
Affected Software
2 affected componentsFixes available
pip/mlflow<2.3.0
2.3.0
Lfprojects Mlflow<2.3.1
Remediation
Event History
May 17, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Advisory Published
09:30 PM
Frequently Asked Questions
1
What is CVE-2023-2780?
CVE-2023-2780 is a path traversal vulnerability in the GitHub repository mlflow/mlflow prior to version 2.3.1.
2
How severe is CVE-2023-2780?
CVE-2023-2780 has a severity rating of 9.8 (critical).
3
Which software versions are affected by CVE-2023-2780?
CVE-2023-2780 affects mlflow/mlflow versions prior to 2.3.1.
4
How can I fix CVE-2023-2780?
To fix CVE-2023-2780, update your mlflow/mlflow version to 2.3.1 or later.
5
What is the CWE number associated with CVE-2023-2780?
The CWE numbers associated with CVE-2023-2780 are 22 and 29.