S4E just found a high-severity finding from cve-2025-58360 scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Feb 18, 2024

CVE-2023-6909 Scanner

CVE-2023-6909 scanner - Path Traversal vulnerability in mlflow

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.2k
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
1
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-6909
7.5
CVSShigh
Exploitable remotely over the internet · no authentication required.

Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.9.2.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
mlflow/mlflowby mlflow
AFFECTED< 2.9.2SAFE ✓≥ 2.9.2
Updated Aug 22, 2026View on NVD →
Detail

Vulnerability Overview

The vulnerability is caused by improper handling of file paths, allowing attackers to traverse the server's directory structure and access files outside of the restricted directories. This could lead to the disclosure of sensitive files and information.

Vulnerability Details

The Mlflow application before version 2.9.2 does not adequately sanitize user-supplied input to file path parameters. An attacker can exploit this by crafting a request that includes directory traversal character sequences (e.g., '..\filename'). This can result in unauthorized access to sensitive files on the server, such as SSH keys, configuration files, or other critical data, leading to information disclosure or further exploitation.

Possible Effects

An attacker exploiting this vulnerability could:

  • Gain access to sensitive files, including configuration files, credentials, and private keys.
  • Potentially escalate privileges or move laterally within the network.
  • Use the disclosed information to plan further attacks against the infrastructure.

Why Choose S4E

S4E provides a comprehensive platform for identifying and mitigating vulnerabilities like CVE-2023-6909. Our tools are user-friendly and designed for both technical and non-technical users, offering detailed insights and remediation guidance. By joining our platform, you gain access to a wealth of cybersecurity resources and support to protect your digital assets effectively.

References

Solution Advice
  • Upgrade Immediately: Update Mlflow to version 2.9.2 or higher as soon as possible.
  • Access Control: Ensure proper access controls and permissions are set on sensitive files and directories.
  • Monitoring and Logging: Implement monitoring and logging to detect any unauthorized access attempts.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.