Cross-site Scripting in MLFlow
High severity
GitHub Reviewed
Published
Feb 24, 2024
to the GitHub Advisory Database
•
Updated Feb 26, 2024
Description
Published by the National Vulnerability Database
Feb 23, 2024
Published to the GitHub Advisory Database
Feb 24, 2024
Last updated
Feb 26, 2024
Reviewed
Feb 26, 2024
Insufficient sanitization in MLflow leads to XSS when running an untrusted recipe.
This issue leads to a client-side RCE when running an untrusted recipe in Jupyter Notebook.
The vulnerability stems from lack of sanitization over template variables.
References