Database/AI/ML frameworks & serving
MLflow: Absolute path traversal prior to 2.5.0
CVSS 10.0CVE-2023-3765AI/ML frameworks & servingcurated
Impact
Absolute path traversal prior to 2.5.0
Who can reach it
Unauthenticated network
What to do
Upgrade to 2.5.0+
References
Related entries
- MLflow: Path traversal prior to 2.3.1CVE-2023-2780 · MLflowCritical
- MLflow: Arbitrary account creation bypassing authenticationCVE-2023-6014 · MLflowCritical
- MLflow: Overwrite any file on the MLflow host without authenticationCVE-2023-6018 · MLflowCritical
- TorchServe: Unauthenticated SSRFCVE-2023-43654 · TorchServeCritical
- BentoML: Insecure deserializationCVE-2024-2912 · BentoMLCritical
- llama.cpp (RPC backend): Unsafe `data` pointer in `rpc_tensor`CVE-2024-42479 · llama.cpp (RPC backend)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.