MLflow versions prior to 2.11.3 are vulnerable to a Path Traversal attack due to improper URI fragment parsing. This vulnerability allows attackers to read arbitrary files on the server, potentially exposing sensitive information.
id: CVE-2024-2928
info:
name: MLflow < 2.11.3 - Path Traversal
author: jyjyjy25,gy741,oriing,AN
...