{"id":"CVE-2023-6976","summary":"Unrestricted Upload of File with Dangerous Type","details":"This vulnerability is capable of writing arbitrary files into arbitrary locations on the remote filesystem in the context of the server process.","aliases":["BIT-mlflow-2023-6976","GHSA-wv8q-4f85-2p8p","PYSEC-2026-1662"],"modified":"2026-08-12T15:14:53.047894Z","published":"2023-12-20T05:30:08.540Z","database_specific":{"cna_assigner":"@huntr_ai","cwe_ids":["CWE-434"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/6xxx/CVE-2023-6976.json"},"references":[{"type":"WEB","url":"https://huntr.com/bounties/2408a52b-f05b-4cac-9765-4f74bac3f20f"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/6xxx/CVE-2023-6976.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-6976"},{"type":"FIX","url":"https://github.com/mlflow/mlflow/commit/5044878da0c1851ccfdd5c0a867157ed9a502fbc"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/mlflow/mlflow","events":[{"introduced":"0"},{"fixed":"6ca72469b289e77acc2f1201ca39237fc025c090"},{"fixed":"5044878da0c1851ccfdd5c0a867157ed9a502fbc"}],"database_specific":{"cpe":"cpe:2.3:a:lfprojects:mlflow:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"2.9.2"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["v2.9.1","v2.9.0","v2.2.0","v1.7.0","1.0.0","v0.8.1","v0.8.0","v0.7","v0.6.0","v0.5.0","v0.4.2","v0.4.1","v0.4.0","v0.3.0","v0.2.1","v0.2.0"],"database_specific":{"vanir_signatures_modified":"2026-08-12T15:14:53Z","vanir_signatures":[{"signature_version":"v1","source":"https://github.com/mlflow/mlflow/commit/6ca72469b289e77acc2f1201ca39237fc025c090","target":{"file":"mlflow/java/scoring/src/test/java/org/mlflow/ScoringServerTest.java","function":"testScoringServerWithValidPredictorRespondsToVersionCorrectly"},"deprecated":false,"digest":{"function_hash":"41577576781758645994132782347271038383","length":482},"id":"CVE-2023-6976-264721b0","signature_type":"Function"},{"deprecated":false,"digest":{"line_hashes":["196573444960829707875320866494714691261","271948446609272190247368243181800837017","53471754088520627507579338316850690467","33278243910103464003635330866461910749"],"threshold":0.9},"id":"CVE-2023-6976-3b2c929e","signature_type":"Line","signature_version":"v1","source":"https://github.com/mlflow/mlflow/commit/6ca72469b289e77acc2f1201ca39237fc025c090","target":{"file":"mlflow/java/scoring/src/main/java/org/mlflow/sagemaker/ScoringServer.java"}},{"deprecated":false,"digest":{"line_hashes":["309731809211771193513369395030748044361","114807972603507761925102257914653220858","54242903575207562870989186276313247961","128921726128245671312574701825963265888"],"threshold":0.9},"id":"CVE-2023-6976-708d66a9","signature_type":"Line","signature_version":"v1","source":"https://github.com/mlflow/mlflow/commit/6ca72469b289e77acc2f1201ca39237fc025c090","target":{"file":"mlflow/java/scoring/src/test/java/org/mlflow/ScoringServerTest.java"}},{"id":"CVE-2023-6976-e5d1dbd1","signature_type":"Function","signature_version":"v1","source":"https://github.com/mlflow/mlflow/commit/6ca72469b289e77acc2f1201ca39237fc025c090","target":{"file":"mlflow/java/scoring/src/main/java/org/mlflow/sagemaker/ScoringServer.java","function":"doGet"},"deprecated":false,"digest":{"length":188,"function_hash":"9624725844488257082857400704039181297"}}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-6976.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}