PT-2024-18156 · Mlflow · Mlflow

CVE-2024-1593

·

Published

2024-04-15

·

Updated

2026-07-07

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions mlflow/mlflow (affected versions not specified)
Description A path traversal issue exists due to improper handling of URL parameters. Attackers can manipulate the 'params' portion of the URL by smuggling path traversal sequences using the ';' character, allowing unauthorized access to files or directories. This enables arbitrary data smuggling into the 'params' part of the URL, leading to potential unauthorized information disclosure or server compromise.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-MLFLOW-2024-1593
CVE-2024-1593
GHSA-F42M-MVFV-CGW5
PYSEC-2026-1649

Affected Products

Mlflow