CVE-2023-6018
The mlflow web server includes tools for tracking experiments, packaging code into reproducible runs, and sharing and deploying models. As this vulnerability allows to write / overwrite any file on the file system, it gives a lot of ways to archive code execution (like overwriting /home/<user>/.bashrc). A malicious user could use this issue to get command execution on the vulnerable machine and get access to data & models information.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://nvd.nist.gov/vuln/detail/CVE-2023-6018, https://github.com/mlflow/mlflow/commit/55c72d02380e8db8118595a4fdae7879cb7ac5bd, https://github.com/mlflow/mlflow, https://huntr.com/bounties/7cf918b5-43f4-48c0-a371-4d963ce69b30, https://pypi.org/project/mlflow, https://github.com/advisories/GHSA-5p3h-7fwh-92rc