This vulnerability is capable of writing arbitrary files into arbitrary locations on the remote filesystem in the context of the server process.
References
Link | Resource |
---|---|
https://github.com/mlflow/mlflow/commit/5044878da0c1851ccfdd5c0a867157ed9a502fbc | Patch |
https://huntr.com/bounties/2408a52b-f05b-4cac-9765-4f74bac3f20f | Exploit Third Party Advisory |
Configurations
History
No history.
Information
Published : 2023-12-20 06:15
Updated : 2023-12-29 16:44
NVD link : CVE-2023-6976
Mitre link : CVE-2023-6976
CVE.ORG link : CVE-2023-6976
JSON object : View
Products Affected
lfprojects
- mlflow
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type