Логотип exploitDog
bind:CVE-2024-3573
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-3573

Количество 2

Количество 2

nvd логотип

CVE-2024-3573

почти 2 года назад

mlflow/mlflow is vulnerable to Local File Inclusion (LFI) due to improper parsing of URIs, allowing attackers to bypass checks and read arbitrary files on the system. The issue arises from the 'is_local_uri' function's failure to properly handle URIs with empty or 'file' schemes, leading to the misclassification of URIs as non-local. Attackers can exploit this by crafting malicious model versions with specially crafted 'source' parameters, enabling the reading of sensitive files within at least two directory levels from the server's root.

CVSS3: 9.3
EPSS: Низкий
github логотип

GHSA-hq88-wg7q-gp4g

почти 2 года назад

mlflow vulnerable to Path Traversal

CVSS3: 9.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-3573

mlflow/mlflow is vulnerable to Local File Inclusion (LFI) due to improper parsing of URIs, allowing attackers to bypass checks and read arbitrary files on the system. The issue arises from the 'is_local_uri' function's failure to properly handle URIs with empty or 'file' schemes, leading to the misclassification of URIs as non-local. Attackers can exploit this by crafting malicious model versions with specially crafted 'source' parameters, enabling the reading of sensitive files within at least two directory levels from the server's root.

CVSS3: 9.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-hq88-wg7q-gp4g

mlflow vulnerable to Path Traversal

CVSS3: 9.3
0%
Низкий
почти 2 года назад

Уязвимостей на страницу