CVE-2023-6977: Path Traversal: '\..\filename'
Published Dec 20, 2023
·Updated
This vulnerability enables malicious users to read sensitive files on the server.
Affected Software
2 affected componentsFixes available
pip/mlflow<2.9.2
2.9.2
Lfprojects Mlflow>=1.0.0<2.9.2
Remediation
Event History
Dec 20, 2023
CVE Published
05:37 AM
Data Sourced
05:37 AM
DescriptionSeverityWeakness
Advisory Published
06:30 AM
Frequently Asked Questions
1
What is the severity of CVE-2023-6977?
CVE-2023-6977 is categorized as a high severity vulnerability due to its potential to expose sensitive files to malicious users.
2
How do I fix CVE-2023-6977?
To fix CVE-2023-6977, upgrade the mlflow package to version 2.9.2 or above.
3
What types of sensitive files can be accessed due to CVE-2023-6977?
CVE-2023-6977 allows unauthorized access to various sensitive files on the server that could include configuration and user data.
4
Which versions of mlflow are affected by CVE-2023-6977?
CVE-2023-6977 affects mlflow versions from 1.0.0 up to but not including 2.9.2.
5
Can I mitigate the risks associated with CVE-2023-6977 without upgrading?
Mitigating the risks of CVE-2023-6977 without upgrading is challenging and involves implementing strict access controls and monitoring.