Description
An attacker can overwrite any file on the server hosting MLflow without any authentication.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-5p3h-7fwh-92rc | Remote Code Execution due to Full Controled File Write in mlflow |
References
History
No history.
Status: PUBLISHED
Assigner: @huntr_ai
Published:
Updated: 2024-08-02T08:21:17.069Z
Reserved: 2023-11-08T09:12:29.945Z
Link: CVE-2023-6018
No data.
Status : Modified
Published: 2023-11-16T16:15:34.880
Modified: 2024-11-21T08:42:59.413
Link: CVE-2023-6018
No data.
OpenCVE Enrichment
No data.
Weaknesses
Github GHSA