Vulnerability index

Browse CVEs

103 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Mlflow CRITICAL 9.8
CVE-2023-6014

An attacker is able to arbitrarily create an account in MLflow bypassing any authentication requirment.

No fix yet
Fix from $2,300 2023-11-16
Mlflow CRITICAL 9.8
CVE-2023-6018EPSS 48%

An attacker can overwrite any file on the server hosting MLflow without any authentication.

No fix yet
Fix from $2,300 2023-11-16
Mlflow HIGH 7.5
CVE-2023-6015

MLflow allowed arbitrary files to be PUT onto the server.

Fix: 2.8.1+
Fix from $1,950 2023-11-16
Mlflow HIGH 7.8
CVE-2023-4033

OS Command Injection in GitHub repository mlflow/mlflow prior to 2.6.0.

Fix: 2.6.0+
Fix from $1,950 2023-08-01
Mlflow CRITICAL 10.0
CVE-2023-3765EPSS 68%

Absolute Path Traversal in GitHub repository mlflow/mlflow prior to 2.5.0.

Fix: 2.5.0+
Fix from $2,300 2023-07-19
Mlflow CRITICAL 9.8
CVE-2023-2780EPSS 6%

Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.3.1.

Fix: 2.3.1+
Fix from $2,300 2023-05-17
Mlflow HIGH 7.5
CVE-2023-30172

A directory traversal vulnerability in the /get-artifact API method of the mlflow platform up to v2.0.1 allows attackers to read arbitrary files on t…

Fix: 2.0.1+
Fix from $1,950 2023-05-11
Mlflow HIGH 7.5
CVE-2023-2356

Relative Path Traversal in GitHub repository mlflow/mlflow prior to 2.3.1.

Fix: 2.3.1+
Fix from $1,950 2023-04-28
Apptainer HIGH 7.8
CVE-2023-30549

Apptainer is an open source container platform for Linux. There is an ext4 use-after-free flaw that is exploitable through versions of Apptainer < 1.…

Fix: 1.1.8+
Fix from $1,950 2023-04-25
Vector Packet Processor HIGH 7.5
CVE-2022-46397

FP.io VPP (Vector Packet Processor) 22.10, 22.06, 22.02, 21.10, 21.06, 21.01, 20.09, 20.05, 20.01, 19.08, and 19.04 Generates a Predictable IV with C…

Mitigation only
Fix from $1,950 2023-03-28
Mlflow CRITICAL 9.8
CVE-2023-1177EPSS 70%

Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.2.1.

Fix: 2.2.1+
Fix from $2,300 2023-03-24
Modelina HIGH 8.8
CVE-2023-23619

Modelina is a library for generating data models based on inputs such as AsyncAPI, OpenAPI, or JSON Schema documents. Versions prior to 1.0.0 are vul…

Fix: 1.0.0+
Fix from $1,950 2023-01-26
Mlflow HIGH 7.5
CVE-2022-0736

Insecure Temporary File in GitHub repository mlflow/mlflow prior to 1.23.1.

Fix: 1.23.1+
Fix from $1,950 2022-02-23