CVE-2023-6976

Updated on 20 Dec 2023

Severity

8.8 High severity

Details

CVSS score
8.8
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Overview

About vulnerability

This vulnerability is capable of writing arbitrary files into arbitrary locations on the remote filesystem in the context of the server process.

Details

Affected product:
mlflow
Affected packages:
mlflow @ 2.9.1

Fixes