PT-2024-26681 · Mlflow · Mlflow
Published
2024-04-15
·
Updated
2025-02-04
·
CVE-2024-3573
CVSS v3.1
9.3
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
mlflow/mlflow (affected versions not specified)
Description
The issue arises from the
is local uri function's failure to properly handle URIs with empty or 'file' schemes, leading to the misclassification of URIs as non-local. Attackers can exploit this by crafting malicious model versions with specially crafted source parameters, enabling the reading of sensitive files within at least two directory levels from the server's root. This allows attackers to bypass checks and read arbitrary files on the system.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mlflow