Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[BUG] Security Vulnerability #9530

Closed
1 of 23 tasks
JoeBeeton opened this issue Sep 5, 2023 · 10 comments
Closed
1 of 23 tasks

[BUG] Security Vulnerability #9530

JoeBeeton opened this issue Sep 5, 2023 · 10 comments
Labels
bug Something isn't working

Comments

@JoeBeeton
Copy link

Issues Policy acknowledgement

  • I have read and agree to submit bug reports in accordance with the issues policy

Willingness to contribute

No. I cannot contribute a bug fix at this time.

MLflow version

mlflow, version 2.6.0

System information

Ubuntu 22.04.2
Python 3.10.12

Describe the problem

Security Vulnerability

Tracking information

REPLACE_ME

Code to reproduce issue

Security Vulnerability

Stack trace

REPLACE_ME

Other info / logs

REPLACE_ME

What component(s) does this bug affect?

  • area/artifacts: Artifact stores and artifact logging
  • area/build: Build and test infrastructure for MLflow
  • area/docs: MLflow documentation pages
  • area/examples: Example code
  • area/gateway: AI Gateway service, Gateway client APIs, third-party Gateway integrations
  • area/model-registry: Model Registry service, APIs, and the fluent client calls for Model Registry
  • area/models: MLmodel format, model serialization/deserialization, flavors
  • area/recipes: Recipes, Recipe APIs, Recipe configs, Recipe Templates
  • area/projects: MLproject format, project running backends
  • area/scoring: MLflow Model server, model deployment tools, Spark UDFs
  • area/server-infra: MLflow Tracking server backend
  • area/tracking: Tracking Service, tracking client APIs, autologging

What interface(s) does this bug affect?

  • area/uiux: Front-end, user experience, plotting, JavaScript, JavaScript dev server
  • area/docker: Docker use across MLflow's components, such as MLflow Projects and MLflow Models
  • area/sqlalchemy: Use of SQLAlchemy in the Tracking Service or Model Registry
  • area/windows: Windows support

What language(s) does this bug affect?

  • language/r: R APIs and clients
  • language/java: Java APIs and clients
  • language/new: Proposals for new client languages

What integration(s) does this bug affect?

  • integrations/azure: Azure and Azure ML integrations
  • integrations/sagemaker: SageMaker integrations
  • integrations/databricks: Databricks integrations
@JoeBeeton JoeBeeton added the bug Something isn't working label Sep 5, 2023
@BenWilson2
Copy link
Member

Hi @JoeBeeton thank you for reporting this!
We are currently looking into it and will test some ideas for preventing the reported issue.

@JoeBeeton
Copy link
Author

Hi, no problem. Let me know if you need anything else.

Joe

@github-actions
Copy link

@mlflow/mlflow-team Please assign a maintainer and start triaging this issue.

@JoeBeeton
Copy link
Author

Hi

Any news on this? I've tried to contact the email address provided but with no response after the initial message.
Joe

@JoeBeeton
Copy link
Author

Hi

@BenWilson2 any news?

@JoeBeeton
Copy link
Author

Hi, whoever on the mlflow side has access, please check mlflow-oss-maintainers@googlegroups.com

@B-Step62
Copy link
Collaborator

@JoeBeeton Thank you so much for reporting the vulnerability and terribly sorry for not being responsive. We are working on the fix right now.

@JoeBeeton
Copy link
Author

Thanks, FYI, the cve is CVE-2023-43472 . Do you know when the fix will be released?

@B-Step62
Copy link
Collaborator

It will be released in next release this week.

@JoeBeeContrast
Copy link

Thanks

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working
Projects
None yet
Development

No branches or pull requests

4 participants