CVE-2023-6831: Path Traversal: '\..\filename' in mlflow/mlflow
Published Dec 15, 2023
·Updated
Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.9.2.
Affected Software
2 affected componentsFixes available
pip/mlflow<2.9.2
2.9.2
Lfprojects Mlflow<2.9.2
Remediation
Event History
Dec 15, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
DescriptionSeverityWeakness
Advisory Published
03:30 AM
Frequently Asked Questions
1
What is the severity of CVE-2023-6831?
CVE-2023-6831 has a medium severity rating due to its impact on file system security.
2
How do I fix CVE-2023-6831?
To fix CVE-2023-6831, update the mlflow package to version 2.9.2 or later.
3
What are the potential risks associated with CVE-2023-6831?
If exploited, CVE-2023-6831 could allow attackers to access restricted files on the server.
4
Which versions of mlflow are affected by CVE-2023-6831?
CVE-2023-6831 affects all versions of mlflow prior to 2.9.2.
5
Is CVE-2023-6831 a remote or local vulnerability?
CVE-2023-6831 is a remote vulnerability allowing unauthorized access from an external source.