CVE-2025-52967
- EPSS 0.04%
- Veröffentlicht 23.06.2025 00:00:00
- Zuletzt bearbeitet 23.06.2025 20:16:21
gateway_proxy_handler in MLflow before 3.1.0 lacks gateway_path validation.
CVE-2025-0453
- EPSS 0.09%
- Veröffentlicht 20.03.2025 10:11:02
- Zuletzt bearbeitet 02.04.2025 16:10:48
In mlflow/mlflow version 2.17.2, the `/graphql` endpoint is vulnerable to a denial of service attack. An attacker can create large batches of queries that repeatedly request all runs from a given experiment. This can tie up all the workers allocated ...
CVE-2025-1474
- EPSS 0.05%
- Veröffentlicht 20.03.2025 10:10:20
- Zuletzt bearbeitet 27.03.2025 15:36:42
In mlflow/mlflow version 2.18, an admin is able to create a new user account without setting a password. This vulnerability could lead to security risks, as accounts without passwords may be susceptible to unauthorized access. Additionally, this issu...
CVE-2025-1473
- EPSS 0.03%
- Veröffentlicht 20.03.2025 10:10:20
- Zuletzt bearbeitet 05.08.2025 17:05:22
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Signup feature of mlflow/mlflow versions 2.17.0 to 2.20.1. This vulnerability allows an attacker to create a new account, which may be used to perform unauthorized actions on behalf of t...
CVE-2024-8859
- EPSS 17.16%
- Veröffentlicht 20.03.2025 10:09:53
- Zuletzt bearbeitet 05.08.2025 16:15:20
A path traversal vulnerability exists in mlflow/mlflow version 2.15.1. When users configure and use the dbfs service, concatenating the URL directly into the file protocol results in an arbitrary file read vulnerability. This issue occurs because onl...
CVE-2024-6838
- EPSS 0.11%
- Veröffentlicht 20.03.2025 10:09:11
- Zuletzt bearbeitet 01.04.2025 20:33:56
In mlflow/mlflow version v2.13.2, a vulnerability exists that allows the creation or renaming of an experiment with a large number of integers in its name due to the lack of a limit on the experiment name. This can cause the MLflow UI panel to become...
- EPSS 0.02%
- Veröffentlicht 25.11.2024 14:15:06
- Zuletzt bearbeitet 03.02.2025 15:05:50
Excessive directory permissions in MLflow leads to local privilege escalation when using spark_udf. This behavior can be exploited by a local attacker to gain elevated permissions by using a ToCToU attack. The issue is only relevant when the spark_ud...
CVE-2024-3099
- EPSS 0.06%
- Veröffentlicht 06.06.2024 19:15:59
- Zuletzt bearbeitet 21.11.2024 09:28:53
A vulnerability in mlflow/mlflow version 2.11.1 allows attackers to create multiple models with the same name by exploiting URL encoding. This flaw can lead to Denial of Service (DoS) as an authenticated user might not be able to use the intended mod...
CVE-2024-2928
- EPSS 88.81%
- Veröffentlicht 06.06.2024 19:15:55
- Zuletzt bearbeitet 21.11.2024 09:10:51
A Local File Inclusion (LFI) vulnerability was identified in mlflow/mlflow, specifically in version 2.9.2, which was fixed in version 2.11.3. This vulnerability arises from the application's failure to properly validate URI fragments for directory tr...
CVE-2024-0520
- EPSS 3.58%
- Veröffentlicht 06.06.2024 19:15:51
- Zuletzt bearbeitet 21.11.2024 08:46:46
A vulnerability in mlflow/mlflow version 8.2.1 allows for remote code execution due to improper neutralization of special elements used in an OS command ('Command Injection') within the `mlflow.data.http_dataset_source.py` module. Specifically, when ...