RULE(RULE ID:338905)

Rule General Information
Release Date: 2025-05-14
Rule Name: Mlflow Path Traversal Vulnerability (CVE-2023-6976)
Severity:
CVE ID:
Rule Protection Details
Description: This vulnerability is capable of writing arbitrary files into arbitrary locations on the remote filesystem in the context of the server process.
Impact: An attacker could exploit this vulnerability to have unspecified effect.
Affected OS: Windows, Linux, Others
Reference: https://github.com/mlflow/mlflow/commit/5044878da0c1851ccfdd5c0a867157ed9a502fbc
https://huntr.com/bounties/2408a52b-f05b-4cac-9765-4f74bac3f20f
Solutions
Please refer to announcements or patches release by the vendor: https://github.com/mlflow/mlflow/commit/5044878da0c1851ccfdd5c0a867157ed9a502fbc