CVE-2023-6940

with only one user interaction(download a malicious config), attackers can gain full command execution on the victim system.
Configurations

Configuration 1 (hide)

cpe:2.3:a:lfprojects:mlflow:*:*:*:*:*:*:*:*

History

29 Dec 2023, 16:58

Type Values Removed Values Added
References () https://github.com/mlflow/mlflow/commit/5139b1087d686fa52e2b087e09da66aff86297b1 - () https://github.com/mlflow/mlflow/commit/5139b1087d686fa52e2b087e09da66aff86297b1 - Patch
References () https://huntr.com/bounties/c6f59480-ce47-4f78-a3dc-4bd8ca15029c - () https://huntr.com/bounties/c6f59480-ce47-4f78-a3dc-4bd8ca15029c - Third Party Advisory
CVSS v2 : unknown
v3 : 9.0
v2 : unknown
v3 : 8.8
CPE cpe:2.3:a:lfprojects:mlflow:*:*:*:*:*:*:*:*
Summary
  • (es) Con solo una interacción del usuario (descargar una configuración maliciosa), los atacantes pueden obtener la ejecución completa del comando en el sistema víctima.
First Time Lfprojects
Lfprojects mlflow

19 Dec 2023, 02:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-12-19 02:15

Updated : 2023-12-29 16:58


NVD link : CVE-2023-6940

Mitre link : CVE-2023-6940

CVE.ORG link : CVE-2023-6940


JSON object : View

Products Affected

lfprojects

  • mlflow
CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')