Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-wc6j-5g83-xfm6: mflow vulnerable to directory traversal

A directory traversal vulnerability in the /get-artifact API method of the mlflow platform prior to v2.0.0 allows attackers to read arbitrary files on the server via the path parameter.

ghsa
#vulnerability#git

mflow vulnerable to directory traversal

Moderate severity GitHub Reviewed Published May 11, 2023 to the GitHub Advisory Database • Updated May 11, 2023

Related news

CVE-2023-30172: [BUG] Security Vulnerability · Issue #7166 · mlflow/mlflow

A directory traversal vulnerability in the /get-artifact API method of the mlflow platform up to v2.0.1 allows attackers to read arbitrary files on the server via the path parameter.