Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-15036

Опубликовано: 30 мар. 2026
Источник: redhat
CVSS3: 9.6
EPSS Низкий

Описание

A path traversal vulnerability exists in the extract_archive_to_dir function within the mlflow/pyfunc/dbconnect_artifact_cache.py file of the mlflow/mlflow repository. This vulnerability, present in versions before v3.7.0, arises due to the lack of validation of tar member paths during extraction. An attacker with control over the tar.gz file can exploit this issue to overwrite arbitrary files or gain elevated privileges, potentially escaping the sandbox directory in multi-tenant or shared cluster environments.

A flaw was found in mlflow. A path traversal vulnerability exists in the extract_archive_to_dir function, which is responsible for extracting archives. An attacker who can control the input tar.gz file can exploit this vulnerability due to insufficient validation of paths within the archive. This allows the attacker to overwrite arbitrary files, potentially leading to privilege escalation or escaping the intended sandbox environment in multi-tenant or shared cluster setups.

Отчет

Important: A path traversal vulnerability exists in mlflow, specifically within the extract_archive_to_dir function. This flaw allows an attacker to overwrite arbitrary files and potentially escalate privileges or escape sandbox environments by providing a specially crafted tar.gz file. Red Hat OpenShift AI (RHOAI) is affected by this vulnerability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift AI (RHOAI)rhoai/odh-mlflow-rhel9Affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-training-cuda128-torch29-py312-rhel9Not affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=2452925mlflow: mlflow: Path traversal vulnerability allows arbitrary file overwrite and privilege escalation

EPSS

Процентиль: 45%
0.00579
Низкий

9.6 Critical

CVSS3

Связанные уязвимости

CVSS3: 10
nvd
5 месяцев назад

A path traversal vulnerability exists in the `extract_archive_to_dir` function within the `mlflow/pyfunc/dbconnect_artifact_cache.py` file of the mlflow/mlflow repository. This vulnerability, present in versions before v3.7.0, arises due to the lack of validation of tar member paths during extraction. An attacker with control over the tar.gz file can exploit this issue to overwrite arbitrary files or gain elevated privileges, potentially escaping the sandbox directory in multi-tenant or shared cluster environments.

CVSS3: 9.6
github
5 месяцев назад

MLFlow path traversal vulnerability

EPSS

Процентиль: 45%
0.00579
Низкий

9.6 Critical

CVSS3