CVE-2023-3765: Absolute Path Traversal in mlflow/mlflow
Published Jul 19, 2023
·Updated
Absolute Path Traversal in GitHub repository mlflow/mlflow prior to 2.5.0.
Affected Software
5 affected componentsFixes available
Lfprojects Mlflow<2.5.0
Microsoft Windows
pip/mlflow<2.5.0
2.5.0
All of the following
Lfprojects Mlflow<2.5.0
Microsoft Windows
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/mlflowto a version that resolves this vulnerability.Fixed in 2.5.0
Event History
Jul 19, 2023
CVE Published
via MITRE·12:53 AM
Data Sourced
via MITRE·12:53 AM
DescriptionSeverityWeakness
Data Sourced
01:15 AM
DescriptionWeakness
Data Sourced
via NVD·01:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Advisory Published
03:30 AM
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-3765.
2
What is the severity of CVE-2023-3765?
The severity of CVE-2023-3765 is critical with a severity score of 10.
3
What is the affected software for CVE-2023-3765?
The affected software for CVE-2023-3765 includes GitHub repository mlflow/mlflow prior to version 2.5.0 and Lfprojects Mlflow version up to exclusive 2.5.0.
4
How do I fix CVE-2023-3765?
To fix CVE-2023-3765, update the affected software to version 2.5.0 or higher.
5
Are Microsoft Windows systems vulnerable to CVE-2023-3765?
No, Microsoft Windows systems are not vulnerable to CVE-2023-3765.