CVE-2024-27133
- EPSS 0.2%
- Veröffentlicht 23.02.2024 22:15:55
- Zuletzt bearbeitet 22.01.2025 13:46:56
Insufficient sanitization in MLflow leads to XSS when running a recipe that uses an untrusted dataset. This issue leads to a client-side RCE when running the recipe in Jupyter Notebook. The vulnerability stems from lack of sanitization over dataset t...
CVE-2024-27132
- EPSS 0.26%
- Veröffentlicht 23.02.2024 22:15:55
- Zuletzt bearbeitet 22.01.2025 14:15:26
Insufficient sanitization in MLflow leads to XSS when running an untrusted recipe. This issue leads to a client-side RCE when running an untrusted recipe in Jupyter Notebook. The vulnerability stems from lack of sanitization over template variables...
CVE-2023-6977
- EPSS 86.18%
- Veröffentlicht 20.12.2023 06:15:45
- Zuletzt bearbeitet 21.11.2024 08:44:57
This vulnerability enables malicious users to read sensitive files on the server.
CVE-2023-6976
- EPSS 0.11%
- Veröffentlicht 20.12.2023 06:15:45
- Zuletzt bearbeitet 21.11.2024 08:44:57
This vulnerability is capable of writing arbitrary files into arbitrary locations on the remote filesystem in the context of the server process.
CVE-2023-6975
- EPSS 1.54%
- Veröffentlicht 20.12.2023 06:15:45
- Zuletzt bearbeitet 21.11.2024 08:44:57
A malicious user could use this issue to get command execution on the vulnerable machine and get access to data & models information.
CVE-2023-6974
- EPSS 2.59%
- Veröffentlicht 20.12.2023 06:15:45
- Zuletzt bearbeitet 21.11.2024 08:44:57
A malicious user could use this issue to access internal HTTP(s) servers and in the worst case (ie: aws instance) it could be abuse to get a remote code execution on the victim machine.
CVE-2023-6940
- EPSS 0.15%
- Veröffentlicht 19.12.2023 02:15:45
- Zuletzt bearbeitet 21.11.2024 08:44:52
with only one user interaction(download a malicious config), attackers can gain full command execution on the victim system.
CVE-2023-6909
- EPSS 87.41%
- Veröffentlicht 18.12.2023 04:15:52
- Zuletzt bearbeitet 21.11.2024 08:44:48
Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.9.2.
CVE-2023-6831
- EPSS 80.89%
- Veröffentlicht 15.12.2023 01:15:08
- Zuletzt bearbeitet 21.11.2024 08:44:38
Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.9.2.
CVE-2023-6753
- EPSS 2.29%
- Veröffentlicht 13.12.2023 00:15:07
- Zuletzt bearbeitet 21.11.2024 08:44:29
Path Traversal in GitHub repository mlflow/mlflow prior to 2.9.2.