CVE-2023-6975: Path Traversal: '\..\filename'
Published Dec 20, 2023
·Updated
A malicious user could use this issue to get command execution on the vulnerable machine and get access to data & models information.
Affected Software
2 affected componentsFixes available
pip/mlflow<2.9.2
2.9.2
Lfprojects Mlflow<2.9.2
Remediation
Event History
Dec 20, 2023
CVE Published
05:26 AM
Data Sourced
05:26 AM
DescriptionSeverityWeakness
Advisory Published
06:30 AM
Frequently Asked Questions
1
What is the severity of CVE-2023-6975?
CVE-2023-6975 is considered a high severity vulnerability due to its ability to allow command execution on the vulnerable machine.
2
How do I fix CVE-2023-6975?
To fix CVE-2023-6975, upgrade the mlflow package to version 2.9.2 or later.
3
What kind of access does CVE-2023-6975 allow to a malicious user?
CVE-2023-6975 allows a malicious user to gain command execution on the vulnerable machine and access confidential data and model information.
4
Which versions of mlflow are affected by CVE-2023-6975?
CVE-2023-6975 affects all versions of mlflow prior to 2.9.2.
5
Is CVE-2023-6975 exploitable remotely?
Yes, CVE-2023-6975 can be exploited remotely by a malicious user.