RULE(RULE ID:338459)

Rule General Information
Release Date: 2024-10-09
Rule Name: Mlflow Cross Site Scripting Vulnerability (CVE-2023-6568)
Severity:
CVE ID:
Rule Protection Details
Description: Cross-site Scripting (XSS) - Reflected in GitHub repository mlflow/mlflow prior to 2.9.0.
Impact: An attacker can conduct a cross-site scripting attack to inject malicious client-side scripts into web pages viewed by other users, or to bypass access controls such as the same-origin policy, if affected version is installed.
Affected OS: Windows, Linux, Others
Reference: https://huntr.com/bounties/816bdaaa-8153-4732-951e-b0d92fddf709
https://github.com/mlflow/mlflow/commit/28ff3f94994941e038f2172c6484b65dc4db6ca1
Solutions
Refer to the announcement or patch by the vendor: https://github.com/mlflow/mlflow/commit/28ff3f94994941e038f2172c6484b65dc4db6ca1