.. / CVE-2023-3765

Exploit for MLflow Absolute Path Traversal (CVE-2023-3765)

Description:

Absolute Path Traversal in GitHub repository mlflow/mlflow prior to 2.5.0.

Nuclei Template

View the template here CVE-2023-3765.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2023/CVE-2023-3765.yaml
Copy

References:

https://nvd.nist.gov/vuln/detail/CVE-2023-3765
https://github.com/mlflow/mlflow/commit/6dde93758d42455cb90ef324407919ed67668b9b
https://www.tenable.com/cve/CVE-2023-3765
https://huntr.dev/bounties/4be5fd63-8a0a-490d-9ee1-f33dc768ed76