← Back to browse · API

CVE-2023-6975

Severity
CRITICAL
CVSS
9.8
EPSS
0.02013
Risk score
39.9
CISA KEV
No
PoC
No
Published
2023-12-20
Modified
2024-08-02
First seen
2026-08-08
Aliases
EUVD-2023-3221, GHSA-HH8P-P8MP-GQHM, PYSEC-2026-422
Products
mlflow:mlflow/mlflow, mlflow:mlflow/mlflow unspecified <2.9.2
Sources
euvd EUVD-2023-3221

Description

A malicious user could use this issue to get command execution on the vulnerable machine and get access to data & models information.

References