CVE-2024-1594

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
16/04/2024
Last modified:
03/02/2025

Description

A path traversal vulnerability exists in the mlflow/mlflow repository, specifically within the handling of the `artifact_location` parameter when creating an experiment. Attackers can exploit this vulnerability by using a fragment component `#` in the artifact location URI to read arbitrary files on the server in the context of the server's process. This issue is similar to CVE-2023-6909 but utilizes a different component of the URI to achieve the same effect.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:lfprojects:mlflow:*:*:*:*:*:*:*:* 2.11.3 (excluding)