CVE-2023-6976: Unrestricted Upload of File with Dangerous Type
Published Dec 20, 2023
·Updated
This vulnerability is capable of writing arbitrary files into arbitrary locations on the remote filesystem in the context of the server process.
Affected Software
2 affected componentsFixes available
pip/mlflow<2.9.2
2.9.2
Lfprojects Mlflow<2.9.2
Remediation
Event History
Dec 20, 2023
CVE Published
via MITRE·05:30 AM
Data Sourced
via MITRE·05:30 AM
DescriptionSeverityWeakness
Data Sourced
06:15 AM
DescriptionSeverityWeakness
Advisory Published
06:30 AM
Frequently Asked Questions
1
What is the severity of CVE-2023-6976?
CVE-2023-6976 is categorized as a high-severity vulnerability due to its potential to write arbitrary files to a remote filesystem.
2
How do I fix CVE-2023-6976?
To mitigate CVE-2023-6976, upgrade the mlflow package to version 2.9.2 or later.
3
What software is affected by CVE-2023-6976?
CVE-2023-6976 affects mlflow versions prior to 2.9.2.
4
What type of vulnerability is CVE-2023-6976?
CVE-2023-6976 is an arbitrary file write vulnerability in the context of the server process.
5
Can CVE-2023-6976 lead to data breaches?
Yes, CVE-2023-6976 can potentially lead to data breaches by allowing unauthorized file writes.