CVE-2023-6015: MLflow Arbitrary File Upload
Published Nov 16, 2023
·Updated
MLflow allowed arbitrary files to be PUT onto the server.
Affected Software
2 affected componentsFixes available
pip/mlflow<2.8.1
2.8.1
Lfprojects Mlflow<2.8.1
Event History
Nov 16, 2023
CVE Published
via MITRE·04:06 PM
Data Sourced
via MITRE·04:06 PM
DescriptionSeverityWeakness
Data Sourced
04:15 PM
DescriptionSeverityWeakness
Advisory Published
06:30 PM
Frequently Asked Questions
1
What is the severity of CVE-2023-6015?
The severity of CVE-2023-6015 is critical.
2
How does CVE-2023-6015 affect MLflow?
CVE-2023-6015 allows arbitrary files to be PUT onto the MLflow server.
3
Which version of MLflow is affected by CVE-2023-6015?
MLflow version 2.8.1 (up-to-exclusive) is affected by CVE-2023-6015.
4
How can I fix CVE-2023-6015?
To fix CVE-2023-6015, upgrade to MLflow version 2.8.1 or later.
5
Where can I find more information about CVE-2023-6015?
For more information about CVE-2023-6015, you can refer to the following sources: [Huntr](https://huntr.com/bounties/43e6fb72-676e-4670-a225-15d6836f65d3), [NVD](https://nvd.nist.gov/vuln/detail/CVE-2023-6015), [GitHub](https://github.com/mlflow/mlflow/pull/10330)