Mlflow · Mlflow · CVE-2023-6831
**Name of the Vulnerable Software and Affected Versions**
mlflow/mlflow versions prior to 2.9.2
**Description**
The issue is related to a Path Traversal vulnerability, where the sequence '..filename' can be used to access files outside the intended directory. This vulnerability is present in the mlflow/mlflow GitHub repository.
**Recommendations**
For versions prior to 2.9.2, update to version 2.9.2 or later to resolve the issue.