OS Command Injection in GitHub repository mlflow/mlflow prior to 2.6.0.
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
Link | Tags |
---|---|
https://huntr.dev/bounties/5312d6f8-67a5-4607-bd47-5e19966fa321 | permissions required |
https://github.com/mlflow/mlflow/commit/6dde93758d42455cb90ef324407919ed67668b9b | patch |