First published: Thu Nov 16 2023(Updated: )
An attacker can overwrite any file on the server hosting MLflow without any authentication.
Credit: security@huntr.dev security@huntr.dev
Affected Software | Affected Version | How to fix |
---|---|---|
Lfprojects Mlflow | ||
pip/mlflow | <=2.8.1 | 2.9.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-6018 is a vulnerability that allows an attacker to write or overwrite any file on the file system.
The mlflow package with version up to and including 2.8.1 and Lfprojects Mlflow are affected by CVE-2023-6018.
CVE-2023-6018 has a severity level of critical, with a severity value of 10.
Exploiting CVE-2023-6018 allows an attacker to execute arbitrary code by overwriting files.
To fix CVE-2023-6018, update the mlflow package to a version higher than 2.8.1 or apply any available patches or security updates provided by the vendor.