CVE-2023-6753: Path Traversal in mlflow/mlflow
Published Dec 13, 2023
·Updated
Path Traversal in GitHub repository mlflow/mlflow prior to 2.9.2.
Affected Software
3 affected componentsFixes available
All of the following
Lfprojects Mlflow<2.9.2
Microsoft Windows
pip/mlflow<2.9.2
2.9.2
Remediation
Event History
Dec 13, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Advisory Published
12:30 AM
Frequently Asked Questions
1
What is the severity of CVE-2023-6753?
CVE-2023-6753 has been classified with a medium severity level.
2
How do I fix CVE-2023-6753?
To fix CVE-2023-6753, update the mlflow package to version 2.9.2 or higher.
3
What type of vulnerability is CVE-2023-6753?
CVE-2023-6753 is classified as a Path Traversal vulnerability.
4
Which versions of mlflow are affected by CVE-2023-6753?
CVE-2023-6753 affects all versions of mlflow prior to 2.9.2.
5
What is the potential impact of CVE-2023-6753?
The potential impact of CVE-2023-6753 includes unauthorized access to sensitive files on the server.