S4E just found a high top 10 tcp port service scan
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2023-2356 Scanner

CVE-2023-2356 scanner - Path Traversal vulnerability in mlflow/mlflow (open source project)

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
0
Times Used
by S4E users
0
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-2356
10.0
CVSScritical
Exploitable remotely over the internet · no authentication required.

Relative Path Traversal in GitHub repository mlflow/mlflow prior to 2.3.1.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
mlflow/mlflowby mlflow
AFFECTED< 2.3.1SAFE ✓≥ 2.3.1
Updated Aug 19, 2026View on NVD →
Detail

mlflow/mlflow is an open-source platform that manages end-to-end machine learning life cycles. It is used to track experiments, package code into reproducible runs, and share and deploy models with ease. The platform allows users to compare and reproduce results, reducing the time it takes to go from experimentation to production. This tool is widely used in many industries that implement machine learning systems.

The CVE-2023-2356 vulnerability is a relative path traversal issue that was detected in mlflow/mlflow before version 2.3.1. This vulnerability allowed an attacker to access and read arbitrary files on the server by manipulating the pathname used in an HTTP GET request. It was identified as a high-severity vulnerability, and it could have serious consequences if left unaddressed.

When exploited, this vulnerability could allow unauthorized access to sensitive files containing valuable or confidential information. For example, an attacker could access the server's configuration files, which contain passwords, access keys, or other sensitive data. This could result in data breaches, unauthorized access, or system shutdowns, ultimately leading to losses in revenue, credibility, and trust.

Thanks to the pro features of the s4e.io platform, readers of this article can easily and quickly learn about potential vulnerabilities in their digital assets. This platform provides comprehensive vulnerability scanning that can automatically detect and prioritize potential vulnerabilities, allowing users to take action to minimize their risk. Don't let your digital assets go unprotected; take advantage of the advanced security features available to you.

 

REFERENCES

Solution Advice

To protect against this vulnerability, there are several precautions that can be taken, including:

  • Update mlflow/mlflow to version 2.3.1 or later, which has fixed the vulnerability.
  • Set up proper access controls and user permissions for sensitive directories and files.
  • Implement input validation to prevent malicious input from being passed to the server.
  • Limit the use of relative file paths in HTTP requests.
  • Use tools that scan for vulnerabilities in software to detect and remediate issues quickly.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.