OS Command Injection in GitHub repository mlflow/mlflow prior to 2.6.0.
{
"cna_assigner": "@huntrdev",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/4xxx/CVE-2023-4033.json",
"cwe_ids": [
"CWE-78"
]
}[
{
"target": {
"file": "mlflow/java/scoring/src/main/java/org/mlflow/sagemaker/ScoringServer.java"
},
"source": "https://github.com/mlflow/mlflow/commit/693b694036bac735dae810eaad9622c519550751",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"158201933246649050684175669332133033066",
"190625738861903660691580362111625652695",
"172096855605516421170840787354612637127",
"104809843383114629816838069152060907540"
]
},
"id": "CVE-2023-4033-05fc0e65",
"deprecated": false,
"signature_type": "Line"
},
{
"target": {
"file": "mlflow/java/scoring/src/test/java/org/mlflow/ScoringServerTest.java"
},
"source": "https://github.com/mlflow/mlflow/commit/693b694036bac735dae810eaad9622c519550751",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"16274644192192082878259755174561049540",
"143877553319587094893362891285023289246",
"226220528622614689734168929956988190803",
"167861059151198616996901880751026931574"
]
},
"id": "CVE-2023-4033-23b74466",
"deprecated": false,
"signature_type": "Line"
},
{
"target": {
"file": "mlflow/java/scoring/src/main/java/org/mlflow/sagemaker/ScoringServer.java",
"function": "doGet"
},
"source": "https://github.com/mlflow/mlflow/commit/693b694036bac735dae810eaad9622c519550751",
"signature_version": "v1",
"digest": {
"length": 197.0,
"function_hash": "203326831794420579606451987216225379673"
},
"id": "CVE-2023-4033-57b517c1",
"deprecated": false,
"signature_type": "Function"
},
{
"target": {
"file": "mlflow/java/scoring/src/test/java/org/mlflow/ScoringServerTest.java",
"function": "testScoringServerWithValidPredictorRespondsToVersionCorrectly"
},
"source": "https://github.com/mlflow/mlflow/commit/693b694036bac735dae810eaad9622c519550751",
"signature_version": "v1",
"digest": {
"length": 491.0,
"function_hash": "267333881600464447824922367259571276934"
},
"id": "CVE-2023-4033-70964eaa",
"deprecated": false,
"signature_type": "Function"
}
]