CVE-2023-1177

Source
https://nvd.nist.gov/vuln/detail/CVE-2023-1177
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-1177.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2023-1177
Aliases
Published
2023-03-24T00:00:00Z
Modified
2025-11-28T02:34:30.400011Z
Severity
  • 9.3 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N CVSS Calculator
Summary
Path Traversal: '\..\filename' in mlflow/mlflow
Details

Path Traversal: '..\filename' in GitHub repository mlflow/mlflow prior to 2.2.1.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/1xxx/CVE-2023-1177.json",
    "cna_assigner": "@huntrdev",
    "cwe_ids": [
        "CWE-29"
    ]
}
References

Affected packages

Git / github.com/mlflow/mlflow

Affected ranges

Type
GIT
Repo
https://github.com/mlflow/mlflow
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

1.*

1.0.0

v0.*

v0.2.0
v0.2.1
v0.3.0
v0.4.0
v0.4.1
v0.4.2
v0.5.0
v0.6.0
v0.7
v0.8.0
v0.8.1

v1.*

v1.7.0

Database specific

vanir_signatures

[
    {
        "deprecated": false,
        "signature_type": "Function",
        "signature_version": "v1",
        "digest": {
            "length": 188.0,
            "function_hash": "315695039987599915833795250148533443280"
        },
        "id": "CVE-2023-1177-3d0ffab8",
        "target": {
            "function": "doGet",
            "file": "mlflow/java/scoring/src/main/java/org/mlflow/sagemaker/ScoringServer.java"
        },
        "source": "https://github.com/mlflow/mlflow/commit/ffe005c58dd45e4f200bfb5a77aa5273a57ca39d"
    },
    {
        "deprecated": false,
        "signature_type": "Line",
        "signature_version": "v1",
        "digest": {
            "line_hashes": [
                "184537011841202855010175748683233015740",
                "37052205958489476375165583908706963982",
                "163827101219918441006880180624444697414",
                "297079543708614561370828289053379060808"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2023-1177-5daf1389",
        "target": {
            "file": "mlflow/java/scoring/src/test/java/org/mlflow/ScoringServerTest.java"
        },
        "source": "https://github.com/mlflow/mlflow/commit/ffe005c58dd45e4f200bfb5a77aa5273a57ca39d"
    },
    {
        "deprecated": false,
        "signature_type": "Function",
        "signature_version": "v1",
        "digest": {
            "length": 482.0,
            "function_hash": "110835240179957637795242358676224518213"
        },
        "id": "CVE-2023-1177-87ebdc7e",
        "target": {
            "function": "testScoringServerWithValidPredictorRespondsToVersionCorrectly",
            "file": "mlflow/java/scoring/src/test/java/org/mlflow/ScoringServerTest.java"
        },
        "source": "https://github.com/mlflow/mlflow/commit/ffe005c58dd45e4f200bfb5a77aa5273a57ca39d"
    },
    {
        "deprecated": false,
        "signature_type": "Line",
        "signature_version": "v1",
        "digest": {
            "line_hashes": [
                "203989792986681947897820114496437655629",
                "223341954211807404523867919691887162855",
                "271938718366277703190849776855167632540",
                "235966189990620696098933471156313906891"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2023-1177-b1982522",
        "target": {
            "file": "mlflow/java/scoring/src/main/java/org/mlflow/sagemaker/ScoringServer.java"
        },
        "source": "https://github.com/mlflow/mlflow/commit/ffe005c58dd45e4f200bfb5a77aa5273a57ca39d"
    }
]