S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2023-3765 Scanner

CVE-2023-3765 scanner - Path Traversal vulnerability in mlflow/mlflow

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.5k
Times Used
continuous scan runs
5.5k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-3765
10.0
CVSScritical
Exploitable remotely over the internet · no authentication required.

Absolute Path Traversal in GitHub repository mlflow/mlflow prior to 2.5.0.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
mlflow/mlflowby mlflow
AFFECTED< 2.5.0SAFE ✓≥ 2.5.0
mlflowby lfprojects
AFFECTED< 2.5.0SAFE ✓≥ 2.5.0
Updated Aug 22, 2026View on NVD →
Detail

mlflow/mlflow is a software developed for the purpose of managing machine learning workflows. It is an open-source platform that enables data scientists and engineers to track experiments, package code and models and manage them in a reproducible manner. With its powerful tools and user-friendly interface, it has become a popular choice for many organizations working with machine learning models.

CVE-2023-3765 is a critical vulnerability detected in mlflow/mlflow prior to version 2.5.0. This vulnerability allows a malicious actor to perform an absolute path traversal attack. This can be achieved by manipulating the URL and accessing arbitrary files on the server. An attacker can use this exploit to steal sensitive information, modify files or even disrupt the entire system.

Exploiting this vulnerability can lead to disastrous consequences. In the worst-case scenario, an attacker could gain complete control of the system and access sensitive data. They could also cause significant damage by deleting important files or modifying data, potentially causing a massive financial loss to the organization. Overall, this exploit poses a severe threat to the security and functionality of the system.

Finally, if you're concerned about the security of your digital assets and want to stay informed about potential vulnerabilities, the s4e.io platform can help you achieve this. Using pro features, you can easily and quickly learn about vulnerabilities in your digital assets. The platform provides updated reports of potential threats and offers practical solutions to protect your online presence, giving you the peace of mind you need to focus on growing your business.

 

REFERENCES

Solution Advice

To protect against this vulnerability, users of mlflow/mlflow should take the following precautions:

  • Upgrade to the latest version of the software (2.5.0 or above)
  • Ensure that the system is fully patched and up-to-date
  • Implement network segmentation to limit access to sensitive servers
  • Implement access controls to limit access to authorized personnel only
  • Regularly review application logs and monitor for any suspicious activity

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.