S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2023-2780 Scanner

CVE-2023-2780 scanner - Path Traversal vulnerability in mlflow/mlflow

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.1k
Times Used
continuous scan runs
5.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-2780
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.3.1.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
mlflow/mlflowby mlflow
AFFECTED< 2.3.1SAFE ✓≥ 2.3.1
Updated Aug 22, 2026View on NVD →
Detail

MLflow is an open-source platform that is designed to manage the complete machine learning cycle. It is a library for the execution of machine learning projects and tracks and captures the metadata for the model development. It uses different libraries, frameworks, and tools for various use cases for machine learning and deep learning. The product is widely used for monitoring the machine learning projects for large scale organizations. It provides features like reproducibility, model registry, artifact management, and collaboration across the various teams and stakeholders involved in the project.

CVE-2023-2780 is a path traversal vulnerability that has been detected in the mlflow/mlflow GitHub repository prior to the version 2.3.1. Path traversal is a technique used to exploit a lack of security validation in inputs related to file names or directory paths. This vulnerability allows attackers to read or modify the files outside the root directory by manipulating file names. In this case, an attacker can access confidential files or execute malicious code by using the path traversal technique on the mlflow/mlflow platform.

The exploitation of this vulnerability can lead attackers to access and modify sensitive files on the system, steal credentials from users and compromise the system's security. Attackers can also execute remote code on the machine to gain complete control over the system and achieve their objectives.

Thanks to the pro features of the s4e.io platform, the users can easily and quickly learn about vulnerabilities in their digital assets. s4e.io provides real-time monitoring of digital assets, including web applications, APIs, and databases, using AI-based technology. It also provides comprehensive reporting and analysis of vulnerabilities, allowing organizations to take timely remedial measures and ensure the security of their assets. By using the s4e.io platform, organizations can secure their digital assets and prevent data breaches caused by vulnerabilities such as CVE-2023-2780.

 

REFERENCES

Solution Advice

To protect against this vulnerability, a few precautions can be taken which are as follows:

  • Upgrade to the latest version of mlflow/mlflow which contains the necessary security fixes.
  • Implement strict input validation checks on all inputs related to file names or directory paths.
  • Implement access controls and user permissions to restrict the access to sensitive files and directories.
  • Monitor the system for any unusual activity and perform periodic security audits.
  • Train the employees on the importance of cybersecurity and the best practices to follow to prevent security breaches.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2023-2780 scanner - Path Traversal vulnerability in mlflow/mlflow | S4E