info: name: mlflow cve: CVE-2023-6753 summary: MLflow中的路径遍历漏洞 details: | 在GitHub仓库mlflow/mlflow的2.9.2版本之前存在路径遍历漏洞。 cvss: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H severity: HIGH security_advise: 升级到mlflow>=2.9.2以解决此问题。 rule: version > "0" && version < "2.9.2" references: - https://nvd.nist.gov/vuln/detail/CVE-2023-6753 - https://github.com/mlflow/mlflow/commit/1c6309f884798fbf56017a3cc808016869ee8de4 - https://github.com/mlflow/mlflow - https://huntr.com/bounties/b397b83a-527a-47e7-b912-a12a17a6cfb4