with only one user interaction(download a malicious config), attackers can gain full command execution on the victim system.
2023-12-19T02:15:45.050
2024-11-21T08:44:52.890
Modified
CVSSv3.1: 8.8 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | lfprojects | mlflow | < 2.9.2 | Yes |