Vulnerability index

Browse CVEs

103 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Mlflow HIGH 8.8
CVE-2024-37060

Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.27.0 or newer, enabling a maliciously crafted Recipe…

No fix yet
Fix from $1,950 2024-06-04
Mlflow HIGH 8.8
CVE-2024-37061

Remote Code Execution can occur in versions of the MLflow platform running version 1.11.0 or newer, enabling a maliciously crafted MLproject to execu…

No fix yet
Fix from $1,950 2024-06-04
Mlflow HIGH 8.8
CVE-2024-37054

Deserialization of untrusted data can occur in versions of the MLflow platform running version 0.9.0 or newer, enabling a maliciously uploaded PyFunc…

No fix yet
Fix from $1,950 2024-06-04
Mlflow HIGH 8.8
CVE-2024-37055

Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.24.0 or newer, enabling a maliciously uploaded pmdar…

No fix yet
Fix from $1,950 2024-06-04
Mlflow HIGH 8.8
CVE-2024-37056

Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.23.0 or newer, enabling a maliciously uploaded Light…

No fix yet
Fix from $1,950 2024-06-04
Mlflow HIGH 8.8
CVE-2024-37057

Deserialization of untrusted data can occur in versions of the MLflow platform running version 2.0.0rc0 or newer, enabling a maliciously uploaded Ten…

No fix yet
Fix from $1,950 2024-06-04
Mlflow HIGH 8.8
CVE-2024-37052

Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.1.0 or newer, enabling a maliciously uploaded scikit…

No fix yet
Fix from $1,950 2024-06-04
Mlflow HIGH 8.8
CVE-2024-37053

Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.1.0 or newer, enabling a maliciously uploaded scikit…

No fix yet
Fix from $1,950 2024-06-04
Mlflow MEDIUM 5.4
CVE-2024-4263

A broken access control vulnerability exists in mlflow/mlflow versions before 2.10.1, where low privilege users with only EDIT permissions on an expe…

Fix: 2.12.1+
Fix from $1,600 2024-05-16
Mlflow HIGH 7.5
CVE-2024-3848EPSS 43%

A path traversal vulnerability exists in mlflow/mlflow version 2.11.0, identified as a bypass for the previously addressed CVE-2023-6909. The vulnera…

Fix: 2.12.1+
Fix from $1,950 2024-05-16
Mlflow CRITICAL 9.3
CVE-2024-3573

mlflow/mlflow is vulnerable to Local File Inclusion (LFI) due to improper parsing of URIs, allowing attackers to bypass checks and read arbitrary fil…

Fix: 2.10.0+
Fix from $2,300 2024-04-16
Mlflow HIGH 7.5
CVE-2024-1593

A path traversal vulnerability exists in the mlflow/mlflow repository due to improper handling of URL parameters. By smuggling path traversal sequenc…

Fix: 2.11.3+
Fix from $1,950 2024-04-16
Mlflow HIGH 7.5
CVE-2024-1594

A path traversal vulnerability exists in the mlflow/mlflow repository, specifically within the handling of the `artifact_location` parameter when cre…

Fix: 2.11.3+
Fix from $1,950 2024-04-16
Mlflow HIGH 8.1
CVE-2024-1560

A path traversal vulnerability exists in the mlflow/mlflow repository, specifically within the artifact deletion functionality. Attackers can bypass …

Fix: after 2.9.2
Fix from $1,950 2024-04-16
Mlflow HIGH 7.5
CVE-2024-1483

A path traversal vulnerability exists in mlflow/mlflow version 2.9.2, allowing attackers to access arbitrary files on the server. By crafting a serie…

Fix: 2.12.1+
Fix from $1,950 2024-04-16
Mlflow HIGH 7.5
CVE-2024-1558

A path traversal vulnerability exists in the `_create_model_version()` function within `server/handlers.py` of the mlflow/mlflow repository, due to i…

Fix: 2.12.1+
Fix from $1,950 2024-04-16
Minder HIGH 7.5
CVE-2024-27093

Minder is a Software Supply Chain Security Platform. In version 0.0.31 and earlier, it is possible for an attacker to register a repository with a in…

Fix: after 0.0.31
Fix from $1,950 2024-02-26
Mlflow CRITICAL 9.6
CVE-2024-27132

Insufficient sanitization in MLflow leads to XSS when running an untrusted recipe. This issue leads to a client-side RCE when running an untrusted r…

Fix: after 2.9.2
Fix from $2,300 2024-02-23
Mlflow CRITICAL 9.6
CVE-2024-27133

Insufficient sanitization in MLflow leads to XSS when running a recipe that uses an untrusted dataset. This issue leads to a client-side RCE when run…

Fix: after 2.9.2
Fix from $2,300 2024-02-23
Mlflow CRITICAL 9.8
CVE-2023-6974

A malicious user could use this issue to access internal HTTP(s) servers and in the worst case (ie: aws instance) it could be abuse to get a remote c…

Fix: 2.9.2+
Fix from $2,300 2023-12-20
Mlflow CRITICAL 9.8
CVE-2023-6975

A malicious user could use this issue to get command execution on the vulnerable machine and get access to data & models information.

Fix: 2.9.2+
Fix from $2,300 2023-12-20
Mlflow HIGH 8.8
CVE-2023-6976

This vulnerability is capable of writing arbitrary files into arbitrary locations on the remote filesystem in the context of the server process.

Fix: 2.9.2+
Fix from $1,950 2023-12-20
Mlflow HIGH 7.5
CVE-2023-6977

This vulnerability enables malicious users to read sensitive files on the server.

Fix: 2.9.2+
Fix from $1,950 2023-12-20
Mlflow HIGH 8.8
CVE-2023-6940

with only one user interaction(download a malicious config), attackers can gain full command execution on the victim system.

Fix: 2.9.2+
Fix from $1,950 2023-12-19
Mlflow HIGH 7.5
CVE-2023-6909EPSS 90%

Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.9.2.

Fix: 2.9.2+
Fix from $1,950 2023-12-18
Mlflow HIGH 8.1
CVE-2023-6831

Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.9.2.

Fix: 2.9.2+
Fix from $1,950 2023-12-15
Mlflow HIGH 8.8
CVE-2023-6753

Path Traversal in GitHub repository mlflow/mlflow prior to 2.9.2.

Fix: 2.9.2+
Fix from $1,950 2023-12-13
Mlflow HIGH 8.8
CVE-2023-6709

Improper Neutralization of Special Elements Used in a Template Engine in GitHub repository mlflow/mlflow prior to 2.9.2.

Fix: 2.9.2+
Fix from $1,950 2023-12-12
Mlflow MEDIUM 6.1
CVE-2023-6568

A reflected Cross-Site Scripting (XSS) vulnerability exists in the mlflow/mlflow repository, specifically within the handling of the Content-Type hea…

Fix: after 2.9.0
Fix from $1,600 2023-12-07
Mlflow HIGH 7.5
CVE-2023-43472EPSS 37%

An issue in MLFlow versions 2.8.1 and before allows a remote attacker to obtain sensitive information via a crafted request to REST API.

Fix: after 2.8.1
Fix from $1,950 2023-12-05