Vulnerability CVE-2023-6977


Published: 2023-12-20

Description:
This vulnerability enables malicious users to read sensitive files on the server.

Type:

CWE-29

(Path Traversal: '\..\filename')

 References:
https://huntr.com/bounties/fe53bf71-3687-4711-90df-c26172880aaf
https://github.com/mlflow/mlflow/commit/4bd7f27c810ba7487d53ed5ef1038fca0f8dc28c

Copyright 2026, cxsecurity.com

 

Back to Top