CVE-2023-6909 is a high-severity path traversal vulnerability affecting mlflow/mlflow versions prior to 2.9.2, allowing an unauthenticated attacker to access arbitrary files on the server. With a CVSS score of 7.5, this vulnerability is easily exploitable over the network without user interaction, potentially leading to critical information disclosure. While not currently in CISA's KEV catalog, public Nuclei templates exist, and its high EPSS score and community discussion indicate a significant likelihood of future exploitation. SecurityWeek has also reported on this vulnerability as part of broader AI supply chain concerns.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.9.2CPE matchmatch criteria | cpe:2.3:a:lfprojects:mlflow:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.