Vulnerability CVE-2023-6976


Published: 2023-12-20

Description:
This vulnerability is capable of writing arbitrary files into arbitrary locations on the remote filesystem in the context of the server process.

Type:

CWE-434

(Unrestricted Upload of File with Dangerous Type)

 References:
https://huntr.com/bounties/2408a52b-f05b-4cac-9765-4f74bac3f20f
https://github.com/mlflow/mlflow/commit/5044878da0c1851ccfdd5c0a867157ed9a502fbc

Copyright 2026, cxsecurity.com

 

Back to Top