Cyber Resilience

CVE-2023-3765

Path Traversal in Lfprojects Mlflow ≤ 2.5.0

Public PoCHigh EPSSPath Traversal
Published
19 July 2023
Modified
21 November 2024
Patch / advisory
CVSS Score v3.1 10.0
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS Score 0.68 99.2th percentile
Risk Priority 100 floored blend · peak EPSS

Summary

CVE-2023-3765 is a critical-severity Absolute Path Traversal (CWE-36) vulnerability in Lfprojects Mlflow. Its CVSS base score is 10.0 (Critical).

Operationally, exploitation aligns with the MITRE ATT&CK technique Exploit Public-Facing Application (T1190); ranked in the top 0.8% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog; a public proof-of-concept is referenced.

Deeper analysis AI-assisted summary

Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.

CVE-2023-3765 is an absolute path traversal vulnerability, tracked as CWE-36, that affects the MLflow machine-learning platform in the GitHub repository mlflow/mlflow prior to version 2.5.0. The flaw received a CVSS 3.1 base score of 10.0, reflecting network attack vector, low attack complexity, no required privileges or user interaction, and changed scope that can produce total loss of confidentiality, integrity, and availability.

An unauthenticated attacker reachable over the network can supply crafted paths that escape intended directories, enabling arbitrary file read or write operations on the server hosting the MLflow instance and potentially leading to full system compromise.

The referenced GitHub commit 6dde93758d42455cb90ef324407919ed67668b9b and the associated huntr.dev report indicate that the issue is resolved by upgrading to MLflow 2.5.0 or later. The EPSS score has reached a peak of 0.9279 with a current value of 0.9145, and the affected component is widely used in machine-learning workflows.

OWASP Top 10 for Web (2025)

EU & UK References

Vulnerability Data

Absolute Path Traversal in GitHub repository mlflow/mlflow prior to 2.5.0.

CWE(s)

Related Threats

MITRE ATT&CK Enterprise Techniques

T1190 Exploit Public-Facing Application Initial Access
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.
Derived from this CVE’s CWE(s) via the direct CWE→ATT&CK cross-walk.

CVEs Like This One

CVE-2023-6753Same product: Lfprojects Mlflow
CVE-2023-1176Same product: Lfprojects Mlflow
CVE-2024-21323Same vendor: Microsoft
CVE-2024-1593Same product: Lfprojects Mlflow
CVE-2023-30172Same product: Lfprojects Mlflow
CVE-2023-32054Same vendor: Microsoft
CVE-2023-6015Same product: Lfprojects Mlflow
CVE-2023-36786Same vendor: Microsoft
CVE-2024-1594Same product: Lfprojects Mlflow
CVE-2026-57211Same product: Microsoft Windows

Affected Assets

lfprojects
mlflow
≤ 2.5.0

Mitigating Controls

Mitigating Controls (NIST CSF 2.0) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.

PR.PS-06 mostly match
prevents

Secure SDLC practices directly require input validation and path sanitization that prevent absolute path traversal.

Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.

finds

Security testing in development can detect absolute path traversal via static analysis and fuzzing.

prevents

Secure development lifecycle includes input validation and path-handling requirements that reduce absolute path traversal risk.

prevents

Application security requirements typically mandate controls against path traversal in file-access functions.

prevents

Secure architecture principles call for canonicalization and sandboxing that limit absolute path traversal.

prevents

Secure coding standards directly require neutralization of absolute path sequences in pathname construction.

mitigates

Information access restriction limits which files can be reached but does not address the path-construction flaw itself.

References