Vulnerabilities (CVE)

Filtered by vendor Lfprojects Subscribe
Filtered by product Mlflow
Total 22 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-30172 1 Lfprojects 1 Mlflow 2024-02-04 N/A 7.5 HIGH
A directory traversal vulnerability in the /get-artifact API method of the mlflow platform up to v2.0.1 allows attackers to read arbitrary files on the server via the path parameter.
CVE-2022-0736 1 Lfprojects 1 Mlflow 2024-02-04 5.0 MEDIUM 7.5 HIGH
Insecure Temporary File in GitHub repository mlflow/mlflow prior to 1.23.1.