CVE-2023-3765
Absolute Path Traversal in GitHub repository mlflow/mlflow prior to 2.5.0.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 10
- CVSS vector
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- EPSS probability
- 92.10%
- CWE
- CWE-36
- Published
- 2023-07-19
- Last modified
- 2026-03-13
Affected products
- mlflow mlflow/mlflow
Weakness type
Related vulnerabilities
- CVE-2024-48248 — NAKIVO Backup & Replication before 11.0.0.88174 allows absolute path traversal for reading files via getImageByPath to /
- CVE-2024-13161 — Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Up
- CVE-2024-13160 — Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Up
- CVE-2024-13159 — Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Up
- CVE-2018-20250 — In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
- CVE-2025-57790 — Path Traversal Vulnerability
- CVE-2021-21586 — Wyse Management Suite versions 3.2 and earlier contain an absolute path traversal vulnerability. A remote authenticated
- CVE-2024-20401 — A vulnerability in the content scanning and message filtering features of Cisco Secure Email Gateway could allow an unau