First published: Wed Jul 19 2023(Updated: )
Absolute Path Traversal in GitHub repository mlflow/mlflow prior to 2.5.0.
Credit: security@huntr.dev security@huntr.dev security@huntr.dev
Affected Software | Affected Version | How to fix |
---|---|---|
pip/mlflow | <2.5.0 | 2.5.0 |
Lfprojects Mlflow | <2.5.0 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-3765.
The severity of CVE-2023-3765 is critical with a severity score of 10.
The affected software for CVE-2023-3765 includes GitHub repository mlflow/mlflow prior to version 2.5.0 and Lfprojects Mlflow version up to exclusive 2.5.0.
To fix CVE-2023-3765, update the affected software to version 2.5.0 or higher.
No, Microsoft Windows systems are not vulnerable to CVE-2023-3765.