Local File Inclusion Vulnerability in mlflow Affects Version 2.9.2
CVE-2024-2928

7.5HIGH

Key Information:

Vendor

Mlflow

Vendor
CVE Published:
6 June 2024

What is CVE-2024-2928?

A Local File Inclusion (LFI) vulnerability exists in MLflow versions prior to 2.11.3, specifically identified in version 2.9.2. This flaw is due to the application's inadequate validation of URI fragments, allowing attackers to exploit directory traversal sequences such as '../'. By manipulating the fragment part of the URI, attackers could potentially access sensitive files on the local file system, including critical files like '/etc/passwd'. This vulnerability effectively bypasses prior patches that only addressed URI query string manipulations, underscoring the necessity for thorough validation across all URI components to mitigate risks associated with LFI attacks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

mlflow/mlflow < 2.11.3

References

EPSS Score

91% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.