Local File Inclusion (LFI) via Scheme Confusion in mlflow/mlflow
Published Apr 16, 2024
9.3
CRITICALCVSS 3.1
EPSS 0.73%
Description
mlflow/mlflow is vulnerable to Local File Inclusion (LFI) due to improper parsing of URIs, allowing attackers to bypass checks and read arbitrary files on the system. The issue arises from the 'is_local_uri' function's failure to properly handle URIs with empty or 'file' schemes, leading to the misclassification of URIs as non-local. Attackers can exploit this by crafting malicious model versions with specially crafted 'source' parameters, enabling the reading of sensitive files within at least two directory levels from the server's root.
Affected products
-
- Version unspecifiedStatusaffectedConstraints<2.10.0
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Mlflow | Mlflow/mlflow | n/a |
|
- < 2.10.0
-
- Version 0StatusaffectedConstraints<2.10.0
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Lfprojects | Mlflow | n/a |
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (6)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-1218 Advisory
- https://github.com/advisories/GHSA-hq88-wg7q-gp4g Advisory
- https://github.com/mlflow/mlflow/commit/438a450714a3ca06285eeea34bdc6cf79d7f6cbc Patch
- https://github.com/pypa/advisory-database/tree/main/vulns/mlflow/PYSEC-2024-243.yaml
- https://huntr.com/bounties/8ea058a7-4ef8-4baf-9198-bc0147fc543c ExploitIssue TrackingThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-3573
Change history (0)
No recorded changes yet.