CVE-2024-8859

CVSS 3.0 Score 7.5 of 10 (high)

Details

Published Mar 20, 2025
CWE ID 29

Summary

CVE-2024-8859 is a newly identified path traversal vulnerability affecting mlflow version 2.15.1. This issue occurs when users configure and utilize the dbfs service, and subsequently mount it to a local directory. The vulnerability arises due to inadequate validation of the URL, specifically the query and parameters, which allows for arbitrary file reading. Exploitation of this vulnerability is possible if a user directly concatenates the URL into the file protocol, bypassing the intended path checks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share