CVEs (76)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.9.2. |
Path Traversal in GitHub repository mlflow/mlflow prior to 2.9.2. |
Improper Neutralization of Special Elements Used in a Template Engine in GitHub repository mlflow/mlflow prior to 2.9.2. |
A reflected Cross-Site Scripting (XSS) vulnerability exists in the mlflow/mlflow repository, specifically within the handling of the Content-Type header in POST requests. An attacker can inject malicious JavaScript code...Show more |
An issue in MLFlow versions 2.8.1 and before allows a remote attacker to obtain sensitive information via a crafted request to REST API. |
An attacker is able to arbitrarily create an account in MLflow bypassing any authentication requirment. |
An attacker can overwrite any file on the server hosting MLflow without any authentication. |
MLflow allowed arbitrary files to be PUT onto the server. |
OS Command Injection in GitHub repository mlflow/mlflow prior to 2.6.0. |
Absolute Path Traversal in GitHub repository mlflow/mlflow prior to 2.5.0. |
Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.3.1. |
A directory traversal vulnerability in the /get-artifact API method of the mlflow platform up to v2.0.1 allows attackers to read arbitrary files on the server via the path parameter. |
Relative Path Traversal in GitHub repository mlflow/mlflow prior to 2.3.1. |
Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.2.1.
|
Absolute Path Traversal in GitHub repository mlflow/mlflow prior to 2.2.2. |
Insecure Temporary File in GitHub repository mlflow/mlflow prior to 1.23.1. |