← Back to browse · API

CVE-2023-6018

Severity
CRITICAL
CVSS
10.0
EPSS
0.47594
Risk score
56.66
CISA KEV
No
PoC
No
Published
2023-11-16
Modified
2024-08-02
First seen
2026-08-08
Aliases
EUVD-2023-2888, GHSA-5P3H-7FWH-92RC, PYSEC-2026-417
Products
mlflow:mlflow/mlflow unspecified ≤latest
Sources
euvd EUVD-2023-2888

Description

An attacker can overwrite any file on the server hosting MLflow without any authentication.

References