PT-2024-18156 · Mlflow · Mlflow

Published

2024-04-15

·

Updated

2025-02-04

·

CVE-2024-1593

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions mlflow/mlflow (affected versions not specified)
Description A path traversal issue exists due to improper handling of URL parameters. Attackers can manipulate the 'params' portion of the URL by smuggling path traversal sequences using the ';' character, allowing unauthorized access to files or directories. This enables arbitrary data smuggling into the 'params' part of the URL, leading to potential unauthorized information disclosure or server compromise.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Weakness Enumeration

Related Identifiers

BIT-MLFLOW-2024-1593
CVE-2024-1593
GHSA-F42M-MVFV-CGW5

Affected Products

Mlflow