CVE-2023-6709: Improper Neutralization of Special Elements Used in a Template Engine in mlflow/mlflow
Published Dec 12, 2023
·Updated
Improper Neutralization of Special Elements Used in a Template Engine in GitHub repository mlflow/mlflow prior to 2.9.2.
Affected Software
2 affected componentsFixes available
pip/mlflow<2.9.2
2.9.2
Lfprojects Mlflow<2.9.2
Remediation
Event History
Dec 12, 2023
CVE Published
04:05 AM
Data Sourced
04:05 AM
DescriptionSeverityWeakness
Advisory Published
06:30 AM
Frequently Asked Questions
1
What is the severity of CVE-2023-6709?
CVE-2023-6709 is classified as a high-severity vulnerability due to the potential for remote code execution.
2
How do I fix CVE-2023-6709?
To mitigate CVE-2023-6709, upgrade the mlflow package to version 2.9.2 or later.
3
What systems are affected by CVE-2023-6709?
CVE-2023-6709 affects mlflow versions prior to 2.9.2 installed via pip and certain configurations of mlflow.
4
What type of vulnerability is CVE-2023-6709?
CVE-2023-6709 is an improper neutralization vulnerability in a template engine which could lead to security risks.
5
Is there a workaround for CVE-2023-6709?
There is no known workaround for CVE-2023-6709, and the best defense is to upgrade to the patched version.