CVE-2023-1177 is a critical path traversal vulnerability affecting MLflow versions prior to 2.2.1, allowing attackers to access arbitrary files on the server. With a CVSS score of 9.8, this vulnerability is easily exploitable over the network with low attack complexity, potentially leading to complete compromise of confidentiality, integrity, and availability. While not yet in the KEV catalog, exploit intelligence indicates readily available Nuclei templates for critical local file inclusion, suggesting a high likelihood of exploitation. The vulnerability has garnered significant community attention and media coverage, highlighting its severe risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.2.1CPE matchmatch criteria | cpe:2.3:a:lfprojects:mlflow:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.