CVE-2023-6974: Server-Side Request Forgery (SSRF)
A malicious user could use this issue to access internal HTTP(s) servers and in the worst case (ie: aws instance) it could be abuse to get a remote code execution on the victim machine.
Other sources
A malicious user could use this issue to access internal HTTP(s) servers and in the worst case (ie: aws instance) it could be abused to get a remote code execution on the victim machine.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-6974?
CVE-2023-6974 has been classified as a critical severity vulnerability due to the potential for remote code execution.
How do I fix CVE-2023-6974?
To fix CVE-2023-6974, update the mlflow package to version 2.9.2 or higher.
What are the potential impacts of CVE-2023-6974?
The potential impacts of CVE-2023-6974 include unauthorized access to internal HTTP(s) servers and remote code execution on affected machines.
Which versions of mlflow are affected by CVE-2023-6974?
CVE-2023-6974 affects mlflow versions prior to 2.9.2.
Who is at risk from CVE-2023-6974?
Organizations using vulnerable versions of mlflow are at risk from CVE-2023-6974, especially in environments where internal servers are accessible.