Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

AI PRP: Arbitrary File Read in mlflow CVE-2024-2928 #503

Open
frkngksl opened this issue Jun 14, 2024 · 2 comments · May be fixed by #535
Open

AI PRP: Arbitrary File Read in mlflow CVE-2024-2928 #503

frkngksl opened this issue Jun 14, 2024 · 2 comments · May be fixed by #535
Assignees
Labels
Contributor main The main issue a contributor is working on (top of the contribution queue).

Comments

@frkngksl
Copy link
Contributor

Hi,

I want to develop a plugin for mlflow LFI - CVE-2024-2928

Vulnerability Information: This vulnerability enables malicious users to read sensitive files on the server. It also covers CVE-2023-6909 because it is a new bypass. Both CVEs doesn't exist in Tsunami Plugins.

Vulnerable Versions are below the 2.11.3

References:

The vulnerability requires five HTTP requests one is GET and the other four are POST. After creating a model and an experiment after linking them, one can read files on the filesystem.

@frkngksl frkngksl changed the title AI PRP: Arbitrary File Read in mlflow CVE-2023-6977 AI PRP: Arbitrary File Read in mlflow CVE-2024-2928 Jun 14, 2024
@tooryx tooryx added the Contributor queue When a contributor has already one issue/PR in review, we put the following ones on hold with this. label Jun 24, 2024
@tooryx tooryx added Contributor main The main issue a contributor is working on (top of the contribution queue). and removed Contributor queue When a contributor has already one issue/PR in review, we put the following ones on hold with this. labels Aug 19, 2024
@tooryx
Copy link
Member

tooryx commented Aug 19, 2024

Hi @frkngksl,

You can work on this next.

Cheers,
~tooryx

@frkngksl
Copy link
Contributor Author

Thanks @tooryx !

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Contributor main The main issue a contributor is working on (top of the contribution queue).
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants