This vulnerability is capable of writing arbitrary files into arbitrary locations on the remote filesystem in the context of the server process.
{
"source": [
"CPE_FIELD",
"REFERENCES"
],
"cpe": "cpe:2.3:a:lfprojects:mlflow:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "2.9.2"
}
]
}[
{
"target": {
"function": "testScoringServerWithValidPredictorRespondsToVersionCorrectly",
"file": "mlflow/java/scoring/src/test/java/org/mlflow/ScoringServerTest.java"
},
"signature_type": "Function",
"id": "CVE-2023-6976-264721b0",
"source": "https://github.com/mlflow/mlflow/commit/6ca72469b289e77acc2f1201ca39237fc025c090",
"signature_version": "v1",
"deprecated": false,
"digest": {
"function_hash": "41577576781758645994132782347271038383",
"length": 482.0
}
},
{
"target": {
"file": "mlflow/java/scoring/src/main/java/org/mlflow/sagemaker/ScoringServer.java"
},
"signature_type": "Line",
"id": "CVE-2023-6976-3b2c929e",
"source": "https://github.com/mlflow/mlflow/commit/6ca72469b289e77acc2f1201ca39237fc025c090",
"signature_version": "v1",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"196573444960829707875320866494714691261",
"271948446609272190247368243181800837017",
"53471754088520627507579338316850690467",
"33278243910103464003635330866461910749"
]
}
},
{
"target": {
"file": "mlflow/java/scoring/src/test/java/org/mlflow/ScoringServerTest.java"
},
"signature_type": "Line",
"id": "CVE-2023-6976-708d66a9",
"source": "https://github.com/mlflow/mlflow/commit/6ca72469b289e77acc2f1201ca39237fc025c090",
"signature_version": "v1",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"309731809211771193513369395030748044361",
"114807972603507761925102257914653220858",
"54242903575207562870989186276313247961",
"128921726128245671312574701825963265888"
]
}
},
{
"target": {
"function": "doGet",
"file": "mlflow/java/scoring/src/main/java/org/mlflow/sagemaker/ScoringServer.java"
},
"signature_type": "Function",
"id": "CVE-2023-6976-e5d1dbd1",
"source": "https://github.com/mlflow/mlflow/commit/6ca72469b289e77acc2f1201ca39237fc025c090",
"signature_version": "v1",
"deprecated": false,
"digest": {
"function_hash": "9624725844488257082857400704039181297",
"length": 188.0
}
}
]
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-6976.json"
"2026-04-12T10:19:35Z"