S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Dec 10, 2024

CVE-2024-2928 Scanner

CVE-2024-2928 Scanner - Path Traversal vulnerability in MLflow

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.2k
Times Used
continuous scan runs
4.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-2928
7.5
CVSShigh
Exploitable remotely over the internet · no authentication required.

A Local File Inclusion (LFI) vulnerability was identified in mlflow/mlflow, specifically in version 2.9.2, which was fixed in version 2.11.3. This vulnerability arises from the application's failure to properly validate URI fragments for directory traversal sequences such as '../'. An attacker can exploit this flaw by manipulating the fragment part of the URI to read arbitrary files on the local file system, including sensitive files like '/etc/passwd'. The vulnerability is a bypass to a previous patch that only addressed similar manipulation within the URI's query string, highlighting the need for comprehensive validation of all parts of a URI to prevent LFI attacks.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
mlflow/mlflowby mlflow
AFFECTED< 2.11.3SAFE ✓≥ 2.11.3
mlflowby lfprojects
AFFECTED< 2.11.3SAFE ✓≥ 2.11.3
Updated Aug 22, 2026View on NVD →
Detail

Product Overview: MLflow is an open-source platform used for managing the end-to-end machine learning lifecycle. It is employed by data scientists and machine learning engineers for tracking experiments, packaging code for deployment, and reproducing results across different platforms.

Vulnerability Overview: The vulnerability allows attackers to perform path traversal attacks due to improper URI fragment parsing in MLflow versions earlier than 2.11.3. This can result in reading arbitrary files on the server, such as configuration files or sensitive data files.

Vulnerability Details: The issue arises from improper handling of URI fragments, which allows an attacker to bypass access controls and traverse directories. This vulnerability can be exploited by sending specific requests to endpoints that do not validate input properly.

Possible Effects: If exploited, this vulnerability allows attackers to read arbitrary files from the system, potentially exposing sensitive information such as configuration files, user credentials, or other confidential data.

REFERENCES

Solution Advice
  • Upgrade MLflow to version 2.11.3 or later to mitigate this issue.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.