MLFlow Cross-site Scripting vulnerability leads to client-side Remote Code Execution
High severity
GitHub Reviewed
Published
Feb 24, 2024
to the GitHub Advisory Database
•
Updated Aug 6, 2024
Description
Published by the National Vulnerability Database
Feb 23, 2024
Published to the GitHub Advisory Database
Feb 24, 2024
Reviewed
Feb 27, 2024
Last updated
Aug 6, 2024
Insufficient sanitization in MLflow leads to XSS when running a recipe that uses an untrusted dataset. This issue leads to a client-side RCE when running the recipe in Jupyter Notebook. The vulnerability stems from lack of sanitization over dataset table fields.
References