|
|||
Rule General Information |
---|
Release Date: | 2024-10-09 | |
Rule Name: | Mlflow Cross Site Scripting Vulnerability (CVE-2023-6568) | |
Severity: | ||
CVE ID: | ||
Rule Protection Details |
---|
Description: | Cross-site Scripting (XSS) - Reflected in GitHub repository mlflow/mlflow prior to 2.9.0. | |
Impact: | An attacker can conduct a cross-site scripting attack to inject malicious client-side scripts into web pages viewed by other users, or to bypass access controls such as the same-origin policy, if affected version is installed. | |
Affected OS: | Windows, Linux, Others | |
Reference: | https://huntr.com/bounties/816bdaaa-8153-4732-951e-b0d92fddf709 https://github.com/mlflow/mlflow/commit/28ff3f94994941e038f2172c6484b65dc4db6ca1 |
|
Solutions |
---|
Refer to the announcement or patch by the vendor: https://github.com/mlflow/mlflow/commit/28ff3f94994941e038f2172c6484b65dc4db6ca1 |