Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-6568

Опубликовано: 07 дек. 2023
Источник: nvd
CVSS3: 6.5
CVSS3: 6.1
EPSS Средний

Описание

A reflected Cross-Site Scripting (XSS) vulnerability exists in the mlflow/mlflow repository, specifically within the handling of the Content-Type header in POST requests. An attacker can inject malicious JavaScript code into the Content-Type header, which is then improperly reflected back to the user without adequate sanitization or escaping, leading to arbitrary JavaScript execution in the context of the victim's browser. The vulnerability is present in the mlflow/server/auth/init.py file, where the user-supplied Content-Type header is directly injected into a Python formatted string and returned to the user, facilitating the XSS attack.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:lfprojects:mlflow:*:*:*:*:*:*:*:*
Версия до 2.9.0 (включая)

EPSS

Процентиль: 97%
0.33351
Средний

6.5 Medium

CVSS3

6.1 Medium

CVSS3

Дефекты

CWE-79
CWE-79

Связанные уязвимости

CVSS3: 6.5
github
около 2 лет назад

Cross-site Scripting (XSS) in MLflow

EPSS

Процентиль: 97%
0.33351
Средний

6.5 Medium

CVSS3

6.1 Medium

CVSS3

Дефекты

CWE-79
CWE-79