RULE(RULE ID:338640)

Rule General Information
Release Date: 2025-01-07
Rule Name: Mlflow Arbitrary File Read Vulnerability (CVE-2024-8859)
Severity:
CVE ID:
Rule Protection Details
Description: Mlflow before 2.17.0 is susceptible to local file inclusion due to path traversal in GitHub repository mlflow/mlflow. An attacker can potentially obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site.
Impact: An attacker could exploit this vulnerability to have unspecified effect.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.