We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2024-2928

Local File Inclusion (LFI) via URI Fragment Parsing in mlflow/mlflow



Assigner@huntr_ai
Reserved2024-03-26
Published2024-06-06
Updated2024-08-01

Description

A Local File Inclusion (LFI) vulnerability was identified in mlflow/mlflow, specifically in version 2.9.2, which was fixed in version 2.11.3. This vulnerability arises from the application's failure to properly validate URI fragments for directory traversal sequences such as '../'. An attacker can exploit this flaw by manipulating the fragment part of the URI to read arbitrary files on the local file system, including sensitive files like '/etc/passwd'. The vulnerability is a bypass to a previous patch that only addressed similar manipulation within the URI's query string, highlighting the need for comprehensive validation of all parts of a URI to prevent LFI attacks.



HIGH: 7.5CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Product status

Any version before 2.11.3
affected

References

https://huntr.com/bounties/19bf02d7-6393-4a95-b9d0-d6d4d2d8c298

https://github.com/mlflow/mlflow/commit/96f0b573a73d8eedd6735a2ce26e08859527be07

cve.org CVE-2024-2928

nvd.nist.gov CVE-2024-2928

Download JSON

Share this page
https://cve.threatint.com
Subscribe to our newsletter to learn more about our work.