MLflow get-artifact /ajax-api/2.0/mlflow/experiments/create 目录遍历漏洞 (CVE-2023-6909)

2025-05-30 MLflow PoC No

Description

MLflow 是一个机器学习的开源平台。MLflow 开源平台 get-artifact 存在目录遍历漏洞,攻击者可通过路径遍历读取系统所有敏感文件,例如 SSH 密钥或内部配置文件,可能导致敏感信息泄露。

PoC

None yet. Search at https://trap.biu.life/?ref=rss

References

Related Vulnerabilities