Vulnerability index

Browse CVEs

103 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2023-6014 An attacker is able to arbitrarily create an account in MLflow bypassing any authentication requirment. Mlflow No fix yet Fix from $2,3002023-11-16 CRITICAL 9.8 CVE-2023-6018EPSS 48% An attacker can overwrite any file on the server hosting MLflow without any authentication. Mlflow No fix yet Fix from $2,3002023-11-16 HIGH 7.5 CVE-2023-6015 MLflow allowed arbitrary files to be PUT onto the server. Mlflow 2.8.1+ Fix from $1,9502023-11-16 HIGH 7.8 CVE-2023-4033 OS Command Injection in GitHub repository mlflow/mlflow prior to 2.6.0. Mlflow 2.6.0+ Fix from $1,9502023-08-01 CRITICAL 10.0 CVE-2023-3765EPSS 68% Absolute Path Traversal in GitHub repository mlflow/mlflow prior to 2.5.0. Mlflow 2.5.0+ Fix from $2,3002023-07-19 CRITICAL 9.8 CVE-2023-2780EPSS 6% Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.3.1. Mlflow 2.3.1+ Fix from $2,3002023-05-17 HIGH 7.5 CVE-2023-30172 A directory traversal vulnerability in the /get-artifact API method of the mlflow platform up to v2.0.1 allows attackers to read arbitrary files on t… Mlflow 2.0.1+ Fix from $1,9502023-05-11 HIGH 7.5 CVE-2023-2356 Relative Path Traversal in GitHub repository mlflow/mlflow prior to 2.3.1. Mlflow 2.3.1+ Fix from $1,9502023-04-28 HIGH 7.8 CVE-2023-30549 Apptainer is an open source container platform for Linux. There is an ext4 use-after-free flaw that is exploitable through versions of Apptainer < 1.… Apptainer 1.1.8+ Fix from $1,9502023-04-25 HIGH 7.5 CVE-2022-46397 FP.io VPP (Vector Packet Processor) 22.10, 22.06, 22.02, 21.10, 21.06, 21.01, 20.09, 20.05, 20.01, 19.08, and 19.04 Generates a Predictable IV with C… Vector Packet Processor Mitigation only Fix from $1,9502023-03-28 CRITICAL 9.8 CVE-2023-1177EPSS 70% Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.2.1. Mlflow 2.2.1+ Fix from $2,3002023-03-24 HIGH 8.8 CVE-2023-23619 Modelina is a library for generating data models based on inputs such as AsyncAPI, OpenAPI, or JSON Schema documents. Versions prior to 1.0.0 are vul… Modelina 1.0.0+ Fix from $1,9502023-01-26 HIGH 7.5 CVE-2022-0736 Insecure Temporary File in GitHub repository mlflow/mlflow prior to 1.23.1. Mlflow 1.23.1+ Fix from $1,9502022-02-23