CVE-2023-2780

Path Traversal: '\..\filename' in pypi/mlflow

Identifiers

GHSA-wjq3-7jxx-whj9, CVE-2023-2780

Package Slug

pypi/mlflow

Vulnerability

Path Traversal: '..\filename'

Description

Path Traversal: '..\filename' in GitHub repository mlflow/mlflow prior to 2.3.1.

Affected Versions

All versions before 2.3.0

Solution

Upgrade to version 2.3.0 or above.

Last Modified

2023-05-19

source