Back

CRITICAL

Local File Inclusion (LFI) via Scheme Confusion in mlflow/mlflow

Published Apr 16, 2024

Description

mlflow/mlflow is vulnerable to Local File Inclusion (LFI) due to improper parsing of URIs, allowing attackers to bypass checks and read arbitrary files on the system. The issue arises from the 'is_local_uri' function's failure to properly handle URIs with empty or 'file' schemes, leading to the misclassification of URIs as non-local. Attackers can exploit this by crafting malicious model versions with specially crafted 'source' parameters, enabling the reading of sensitive files within at least two directory levels from the server's root.

Affected products

Remediation

No remediation recorded yet.

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner @huntr_ai
Published Apr 16, 2024
Updated Aug 1, 2024
Reserved Apr 10, 2024
CISA Vulnrichment
Updated Jun 17, 2024
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner @huntr_ai
Published Apr 16, 2024
Updated Aug 1, 2024
Exploited since n/a
EUVD-2024-1218 GHSA-HQ88-WG7Q-GP4G