SCA: security update for mlflow (GHSA-f42m-mvfv-cgw5)

high Tenable Self-Hosted Container Security Plugin ID 446938

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- A path traversal vulnerability exists in the mlflow/mlflow repository due to improper handling of URL
parameters. By smuggling path traversal sequences using the ';' character in URLs, attackers can
manipulate the 'params' portion of the URL to gain unauthorized access to files or directories. This
vulnerability allows for arbitrary data smuggling into the 'params' part of the URL, enabling attacks
similar to those described in previous reports but utilizing the ';' character for parameter smuggling.
Successful exploitation could lead to unauthorized information disclosure or server compromise.
(CVE-2024-1593)

Solution

There is no known solution at this time.

See Also

https://github.com/advisories/GHSA-f42m-mvfv-cgw5

Plugin Details

Severity: High

ID: 446938

Version: Revision 1.1

Type: Local

Family: SCA Checks

Published: 8/31/2026

Updated: 8/31/2026

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.93

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.1

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:N/A:N

CVSS Score Source: CVE-2024-1593

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.7

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 4/16/2024

Vulnerability Publication Date: 4/16/2024

Reference Information

CVE: CVE-2024-1593

cwe: CWE-22