CVE-2023-6015
MLflow allowed arbitrary files to be PUT onto the server.
- Affected products
- Mlflow
- Lfprojects Mlflow
- < 2.8.1
- CVSS 3.0
- 10.0 CRITICAL
- EPSS
- 4.4% (90th percentile)
- Weakness
- CWE-22
- NVD status
- Modified
- Published
- 2023-11-16
CVE-2023-6015 at NVD
No indexed exploits for CVE-2023-6015 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2023-6015 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.